Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2022-02-25 CVE-2022-25328 OS Command Injection vulnerability in Google Fscrypt
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances.
local
low complexity
google CWE-78
7.2
2022-02-12 CVE-2022-0289 Use After Free vulnerability in Google Chrome
Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
google CWE-416
6.8
2022-02-12 CVE-2022-0290 Use After Free vulnerability in Google Chrome
Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
network
google CWE-416
6.8
2022-02-12 CVE-2022-0291 Unspecified vulnerability in Google Chrome
Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
network
google
4.3
2022-02-12 CVE-2022-0292 Unspecified vulnerability in Google Chrome
Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
network
google
4.3
2022-02-12 CVE-2022-0293 Use After Free vulnerability in Google Chrome
Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
google CWE-416
6.8
2022-02-12 CVE-2022-0294 Unspecified vulnerability in Google Chrome
Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
network
google
4.3
2022-02-12 CVE-2022-0295 Use After Free vulnerability in Google Chrome
Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.
network
google CWE-416
6.8
2022-02-12 CVE-2022-0296 Use After Free vulnerability in Google Chrome
Use after free in Printing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.
network
google CWE-416
6.8
2022-02-12 CVE-2022-0297 Use After Free vulnerability in Google Chrome
Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
google CWE-416
6.8