VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2022-2010CriJul 28, 2022
    risk 0.61cvss 9.3epss 0.01

    Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-2107HigJul 8, 2019
    risk 0.61cvss 8.8epss 0.09

    In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions:…

  • CVE-2019-5789HigMay 23, 2019
    risk 0.61cvss 8.8epss 0.09

    An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5788HigMay 23, 2019
    risk 0.61cvss 8.8epss 0.09

    An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2018-6126HigJan 9, 2019
    risk 0.61cvss 8.8epss 0.08

    A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

  • CVE-2018-16083HigJan 9, 2019
    risk 0.61cvss 8.8epss 0.05

    An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-16071HigJan 9, 2019
    risk 0.61cvss 8.8epss 0.05

    A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

  • CVE-2016-9651HigJan 9, 2019
    risk 0.61cvss 8.8epss 0.11

    A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2018-6092HigDec 4, 2018
    risk 0.61cvss 8.8epss 0.09

    An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2018-6064HigNov 14, 2018
    risk 0.61cvss 8.8epss 0.07

    Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2016-6754HigNov 25, 2016
    risk 0.61cvss 8.8epss 0.05

    A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of…

  • CVE-2015-8664HigDec 24, 2015
    risk 0.61cvss 8.8epss 0.05

    Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array with crafted dimensions, a…

  • CVE-2026-19485CriAug 26, 2026
    risk 0.60cvss epss 0.00

    A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error…

  • CVE-2026-75062CriAug 26, 2026
    risk 0.60cvss epss 0.00

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the context of the host…

  • CVE-2026-12710CriAug 22, 2026
    risk 0.60cvss epss 0.00

    A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

  • CVE-2026-16416CriJul 21, 2026
    risk 0.60cvss 9.3epss 0.00

    Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-14038CriJun 30, 2026
    risk 0.60cvss 9.3epss 0.00

    Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-2264CriMay 26, 2026
    risk 0.60cvss epss 0.00

    A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure…

  • CVE-2026-7428CriMay 12, 2026
    risk 0.60cvss epss 0.00

    Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database. …

  • CVE-2026-0106CriFeb 5, 2026
    risk 0.60cvss 9.3epss 0.00

    In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-12414CriNov 20, 2025
    risk 0.60cvss epss 0.00

    An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted. Self-hosted…

  • CVE-2024-43093HigKEVNov 13, 2024
    risk 0.60cvss 7.3epss 0.01

    In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution…

  • CVE-2023-6112HigNov 15, 2023
    risk 0.60cvss 8.8epss 0.25

    Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-2724HigMay 16, 2023
    risk 0.60cvss 8.8epss 0.29

    Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-2998HigSep 26, 2022
    risk 0.60cvss 8.8epss 0.30

    Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6551HigSep 21, 2020
    risk 0.60cvss 8.8epss 0.29

    Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6550HigSep 21, 2020
    risk 0.60cvss 8.8epss 0.29

    Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6549HigSep 21, 2020
    risk 0.60cvss 8.8epss 0.29

    Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-20606CriMar 24, 2020
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered on Samsung mobile devices with any (before May 2019) software. A phishing attack against OMACP can change the network and internet settings. The Samsung ID is SVE-2019-14073 (May 2019).

  • CVE-2019-5736HigFeb 11, 2019
    risk 0.60cvss 8.6epss 0.98

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new…

  • CVE-2026-85043CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.00

    Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-84324CriSep 2, 2026
    risk 0.59cvss 9.0epss 0.00

    Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-79148CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.00

    Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

  • CVE-2026-79058CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17666CriJul 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-13872CriJun 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

  • CVE-2026-13852CriJun 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-13851CriJun 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-11153CriJun 4, 2026
    risk 0.59cvss 9.1epss 0.00

    Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-9891CriMay 28, 2026
    risk 0.59cvss 9.0epss 0.00

    Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)

  • CVE-2026-9881CriMay 28, 2026
    risk 0.59cvss 9.0epss 0.00

    Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)

  • CVE-2025-48609CriMar 2, 2026
    risk 0.59cvss 9.1epss 0.00

    In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User…

  • CVE-2026-3061CriFeb 23, 2026
    risk 0.59cvss 9.1epss 0.00

    Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-1727CriFeb 6, 2026
    risk 0.59cvss epss 0.00

    The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This…

  • CVE-2025-10890CriSep 24, 2025
    risk 0.59cvss 9.1epss 0.00

    Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-27207CriMar 11, 2024
    risk 0.59cvss 9.1epss 0.00

    Exported broadcast receivers allowing malicious apps to bypass broadcast protection.

  • CVE-2024-0517HigJan 16, 2024
    risk 0.59cvss 8.8epss 0.22

    Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4362HigAug 15, 2023
    risk 0.59cvss 8.8epss 0.19

    Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4355HigAug 15, 2023
    risk 0.59cvss 8.8epss 0.28

    Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4069HigAug 3, 2023
    risk 0.59cvss 8.8epss 0.25

    Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Page 24 of 318