Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2023-10-02 CVE-2023-32829 Integer Overflow or Wraparound vulnerability in multiple products
In apusys, there is a possible out of bounds write due to an integer overflow.
local
low complexity
linuxfoundation mediatek google CWE-190
6.7
2023-10-02 CVE-2023-32830 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
In TVAPI, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2023-09-28 CVE-2023-5186 Use After Free vulnerability in multiple products
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction.
network
low complexity
google debian fedoraproject CWE-416
8.8
2023-09-28 CVE-2023-5187 Use After Free vulnerability in multiple products
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-416
8.8
2023-09-27 CVE-2023-44121 Unspecified vulnerability in Google Android
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file.
local
low complexity
google
6.3
2023-09-27 CVE-2023-44122 Exposure of Resource to Wrong Sphere vulnerability in Google Android 12.0/13.0
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file.
local
low complexity
google CWE-668
7.8
2023-09-27 CVE-2023-44123 Unspecified vulnerability in Google Android 12.0/13.0
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app.
local
low complexity
google
7.8
2023-09-27 CVE-2023-44124 Exposure of Resource to Wrong Sphere vulnerability in Google Android 12.0/13.0
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file.
local
low complexity
google CWE-668
3.3
2023-09-27 CVE-2023-44125 Unspecified vulnerability in Google Android 12.0/13.0
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app.
local
low complexity
google
7.8
2023-09-27 CVE-2023-44126 Unspecified vulnerability in Google Android
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device.
local
low complexity
google
5.5