VYPR

Vendor CVEs

Google

All CVEs

15,874 total · sorted by risk
  • CVE-2022-4189MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2022-4188MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4186MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.00

    Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4185MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4184MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4183MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4182MedNov 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-39887MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

  • CVE-2022-39884MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

  • CVE-2022-3447MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3661MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)

  • CVE-2022-3660MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 107.0.5304.62 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-3444MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)

  • CVE-2022-3443MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2022-3318MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.00

    Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low)

  • CVE-2022-3317MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 106.0.5249.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2022-3316MedNov 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2022-3474MedOct 26, 2022
    risk 0.28cvss 4.3epss 0.00

    A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

  • CVE-2022-3053MedSep 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.

  • CVE-2022-2619MedAug 12, 2022
    risk 0.28cvss 4.3epss 0.00

    Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.

  • CVE-2022-2611MedAug 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-2479MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.

  • CVE-2022-2165MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2022-1875MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1872MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.

  • CVE-2022-1871MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.

  • CVE-2022-1637MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1498MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1495MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.

  • CVE-2022-1488MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

  • CVE-2022-1307MedJul 25, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-1306MedJul 25, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0118MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0116MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0112MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.

  • CVE-2022-0110MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-23595MedFeb 4, 2022
    risk 0.28cvss 5.3epss 0.01

    Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario, all devices are allowed, so `flr->config_proto` is `nullptr`. The fix will be…

  • CVE-2021-38020MedDec 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-38004MedNov 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37971MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-37968MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37967MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37966MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-37965MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37963MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2021-30630MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

  • CVE-2021-30596MedAug 26, 2021
    risk 0.28cvss 4.3epss 0.02

    Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-30589MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.02

    Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.

  • CVE-2021-30587MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-25430MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

Page 267 of 318