VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2024-3157CriApr 10, 2024
    risk 0.62cvss 9.6epss 0.01

    Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

  • CVE-2019-13690CriAug 25, 2023
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2022-4924CriJul 29, 2023
    risk 0.62cvss 9.6epss 0.01

    Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4920CriJul 29, 2023
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-3420HigJun 26, 2023
    risk 0.62cvss 8.8epss 0.56

    Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3890CriNov 9, 2022
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-1853CriJul 27, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-1312CriJul 25, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2022-1309CriJul 25, 2022
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-0977CriJul 21, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0973CriJul 21, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0790CriApr 5, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-0466CriApr 5, 2022
    risk 0.62cvss 9.6epss 0.01

    Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-0452CriApr 5, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-0097CriFeb 12, 2022
    risk 0.62cvss 9.6epss 0.01

    Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.

  • CVE-2021-38013CriDec 23, 2021
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-38002CriNov 23, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6492CriNov 2, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-37981CriNov 2, 2021
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-30571CriAug 3, 2021
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21151CriFeb 22, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21150CriFeb 22, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21146CriFeb 9, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21142CriFeb 9, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16045CriJan 14, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21111CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2021-21107CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16018CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16016CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16014CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6509CriJul 22, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-6507HigJul 22, 2020
    risk 0.62cvss 8.8epss 0.19

    Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6505CriJul 22, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6469CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-6461CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6457CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-5825MedKEVNov 25, 2019
    risk 0.62cvss 6.5epss 0.56

    Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5850CriNov 25, 2019
    risk 0.62cvss 9.6epss 0.01

    Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-5786MedKEVJun 27, 2019
    risk 0.62cvss 6.5epss 0.62

    Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2017-15402CriJan 9, 2019
    risk 0.62cvss 9.6epss 0.01

    Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer…

  • CVE-2017-0781HigSep 14, 2017
    risk 0.62cvss 8.8epss 0.23

    A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

  • CVE-2026-19410CriAug 31, 2026
    risk 0.61cvss epss 0.00

    An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched…

  • CVE-2026-12717CriAug 26, 2026
    risk 0.61cvss epss 0.00

    An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and…

  • CVE-2026-15623CriAug 17, 2026
    risk 0.61cvss epss 0.00

    A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability…

  • CVE-2026-15587CriAug 5, 2026
    risk 0.61cvss epss 0.00

    Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability…

  • CVE-2026-4764CriJun 11, 2026
    risk 0.61cvss epss 0.00

    A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. …

  • CVE-2026-4810CriApr 13, 2026
    risk 0.61cvss epss 0.02

    A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting…

  • CVE-2025-27038HigKEVJun 3, 2025
    risk 0.61cvss 7.5epss 0.01

    Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

  • CVE-2023-6702HigDec 14, 2023
    risk 0.61cvss 8.8epss 0.44

    Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4357HigAug 15, 2023
    risk 0.61cvss 8.8epss 0.47

    Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Page 23 of 318