VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2026-14121CriJun 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)

  • CVE-2026-14104CriJun 30, 2026
    risk 0.64cvss 9.8epss 0.01

    Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-13776CriJun 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-13775CriJun 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-0126CriJun 16, 2026
    risk 0.64cvss 9.8epss 0.00

    In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-5902CriApr 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0120CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.00

    In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0116CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.00

    In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0114CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.00

    In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0113CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.00

    In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0111CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.00

    In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0110CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.00

    In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-3136CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is…

  • CVE-2026-0006CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-3062CriFeb 23, 2026
    risk 0.64cvss 9.8epss 0.00

    Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-20418CriFeb 2, 2026
    risk 0.64cvss 9.8epss 0.00

    In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465153; Issue ID: MSV-4927.

  • CVE-2026-0907CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.08

    Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0906CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0905CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.00

    Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)

  • CVE-2025-36937CriDec 11, 2025
    risk 0.64cvss 9.8epss 0.00

    In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48626CriDec 8, 2025
    risk 0.64cvss 9.8epss 0.00

    In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-59693CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and…

  • CVE-2025-36904CriSep 4, 2025
    risk 0.64cvss 9.8epss 0.00

    WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

  • CVE-2025-36897CriSep 4, 2025
    risk 0.64cvss 9.8epss 0.00

    In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-36896CriSep 4, 2025
    risk 0.64cvss 9.8epss 0.00

    WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

  • CVE-2025-36890CriSep 4, 2025
    risk 0.64cvss 9.8epss 0.00

    Elevation of Privilege

  • CVE-2025-26416CriSep 2, 2025
    risk 0.64cvss 9.8epss 0.00

    In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22435CriSep 2, 2025
    risk 0.64cvss 9.8epss 0.00

    In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22429CriSep 2, 2025
    risk 0.64cvss 9.8epss 0.00

    In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22408CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22403CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-0075CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-0074CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-6179CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and…

  • CVE-2025-4052CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-49748CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.00

    In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-49747CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.00

    In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20148CriJan 6, 2025
    risk 0.64cvss 9.8epss 0.00

    In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 /…

  • CVE-2024-53842CriJan 3, 2025
    risk 0.64cvss 9.8epss 0.00

    In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9388CriDec 5, 2024
    risk 0.64cvss 9.8epss 0.00

    In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.

  • CVE-2018-9430CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.00

    In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9418CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.00

    In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9479CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.00

    In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for…

  • CVE-2018-9478CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.00

    In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for…

  • CVE-2018-9467CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.00

    In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43091CriNov 13, 2024
    risk 0.64cvss 9.8epss 0.00

    In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20103CriOct 7, 2024
    risk 0.64cvss 9.8epss 0.00

    In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.

  • CVE-2024-20101CriOct 7, 2024
    risk 0.64cvss 9.8epss 0.00

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.

  • CVE-2024-20100CriOct 7, 2024
    risk 0.64cvss 9.8epss 0.00

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.

  • CVE-2024-44097CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.00

    According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection…

Page 3 of 318