Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2024-07-01 CVE-2024-39428 Out-of-bounds Write vulnerability in Google Android 12.0/13.0/14.0
In trusty service, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
4.4
2024-07-01 CVE-2024-39429 Out-of-bounds Write vulnerability in Google Android 12.0
In faceid servive, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.2
2024-07-01 CVE-2024-39430 Out-of-bounds Write vulnerability in Google Android 12.0
In faceid servive, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.2
2024-07-01 CVE-2024-20079 Out-of-bounds Write vulnerability in Google Android 13.0/14.0
In gnss service, there is a possible out of bounds write due to improper input validation.
local
low complexity
google CWE-787
6.7
2024-07-01 CVE-2024-20081 Out-of-bounds Write vulnerability in multiple products
In gnss service, there is a possible out of bounds write due to improper input validation.
6.7
2024-06-26 CVE-2024-38271 Improper Resource Shutdown or Release vulnerability in Google Nearby
There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing.
high complexity
google CWE-404
4.8
2024-06-26 CVE-2024-38272 Authentication Bypass by Capture-replay vulnerability in Google Nearby
There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above
low complexity
google CWE-294
4.3
2024-06-24 CVE-2024-6290 Use After Free vulnerability in multiple products
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
8.8
2024-06-24 CVE-2024-6291 Use After Free vulnerability in multiple products
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
8.8
2024-06-24 CVE-2024-6292 Use After Free vulnerability in multiple products
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
8.8