VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2019-20623LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized memory disclosure. The Samsung ID is SVE-2018-13060 (February 2019).

  • CVE-2019-20533LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019).

  • CVE-2020-0047LowMar 10, 2020
    risk 0.21cvss 3.3epss 0.00

    In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141622311

  • CVE-2019-13762LowDec 10, 2019
    risk 0.21cvss 3.3epss 0.00

    Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.

  • CVE-2019-13679LowNov 25, 2019
    risk 0.21cvss 3.3epss 0.01

    Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.

  • CVE-2019-9440LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions:…

  • CVE-2019-9438LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In the Package Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of information about installed packages for other users with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-9377LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of another user on the device with…

  • CVE-2019-9364LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-9351LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional execution privileges needed. User…

  • CVE-2019-9292LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In the Activity Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of current foreground process with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2019-9280LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In keyguard, there is a possible escalation of privilege due to improper permission checks. This could lead to a local bypass of the keyguard under limited circumstances, with User execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2019-9277LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…

  • CVE-2018-9581LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2018-6254LowMay 10, 2018
    risk 0.21cvss 3.3epss 0.00

    In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference:…

  • CVE-2017-6426LowApr 4, 2018
    risk 0.21cvss 3.3epss 0.00

    An information disclosure vulnerability in the Qualcomm SPMI driver. Product: Android. Versions: Android kernel. Android ID: A-33644474. References: QC-CR#1106842.

  • CVE-2017-6425LowApr 4, 2018
    risk 0.21cvss 3.3epss 0.00

    An information disclosure vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-32577085. References: QC-CR#1103689.

  • CVE-2016-10236LowApr 4, 2018
    risk 0.21cvss 3.3epss 0.00

    An information disclosure vulnerability in the Qualcomm USB driver. Product: Android. Versions: Android kernel. Android ID: A-33280689. References: QC-CR#1102418.

  • CVE-2017-5084LowOct 27, 2017
    risk 0.21cvss 3.3epss 0.00

    Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.

  • CVE-2017-5081LowOct 27, 2017
    risk 0.21cvss 3.3epss 0.00

    Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.

  • CVE-2017-0709LowJul 6, 2017
    risk 0.21cvss 3.3epss 0.00

    A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.

  • CVE-2015-9032LowJun 13, 2017
    risk 0.21cvss 3.3epss 0.00

    In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.

  • CVE-2015-9031LowJun 13, 2017
    risk 0.21cvss 3.3epss 0.00

    In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.

  • CVE-2016-6770LowJan 12, 2017
    risk 0.21cvss 3.3epss 0.00

    An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android.…

  • CVE-2016-3763LowJul 11, 2016
    risk 0.21cvss 3.3epss 0.01

    net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to…

  • CVE-2016-3759LowJul 11, 2016
    risk 0.21cvss 3.3epss 0.00

    The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.

  • CVE-2026-85052LowSep 3, 2026
    risk 0.20cvss 3.1epss 0.00

    Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84359LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84355LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84331LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-84328LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79289LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79272LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79255LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79228LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79203LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79191LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79186LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79103LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79066LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79059LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79053LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79034LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79031LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79007LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79002LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78986LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78958LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78953LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2026-78943LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Page 279 of 318