Vulnerabilities > Google > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-11-20 CVE-2016-9652 Unspecified vulnerability in Google Chrome
Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.
network
low complexity
google
critical
9.8
2019-11-20 CVE-2016-5194 Unspecified vulnerability in Google Chrome
Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
network
low complexity
google
critical
9.8
2019-11-13 CVE-2019-2206 Out-of-bounds Write vulnerability in Google Android
In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check.
network
google CWE-787
critical
9.3
2019-11-13 CVE-2019-2205 Use After Free vulnerability in Google Android
In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free.
network
low complexity
google CWE-416
critical
10.0
2019-11-13 CVE-2019-2204 Out-of-bounds Read vulnerability in Google Android 9.0
In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal.
network
low complexity
google CWE-125
critical
10.0
2019-11-13 CVE-2019-2036 Unspecified vulnerability in Google Android
In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check.
network
low complexity
google
critical
10.0
2019-11-07 CVE-2011-2337 Incorrect Type Conversion or Cast vulnerability in Google Blink
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
network
low complexity
google CWE-704
critical
9.8
2019-11-06 CVE-2014-3180 Out-of-bounds Read vulnerability in multiple products
In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read.
network
low complexity
linux google CWE-125
critical
9.1
2019-10-25 CVE-2016-5202 Incorrect Permission Assignment for Critical Resource vulnerability in Google Chrome
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
network
low complexity
google CWE-732
critical
9.1
2019-10-11 CVE-2019-2186 Out-of-bounds Write vulnerability in Google Android
In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check.
network
google CWE-787
critical
9.3