Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-25 CVE-2021-0941 Use After Free vulnerability in Google Android
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free.
local
low complexity
google CWE-416
7.2
2021-10-22 CVE-2021-0652 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects.
local
low complexity
google CWE-119
7.2
2021-10-22 CVE-2021-0703 Use After Free vulnerability in Google Android 11.0
In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage.
local
low complexity
google CWE-416
7.2
2021-10-22 CVE-2021-0705 Unspecified vulnerability in Google Android 10.0/11.0
In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions.
local
low complexity
google
7.2
2021-10-22 CVE-2021-0708 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android
In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy.
local
low complexity
google CWE-610
7.2
2021-10-08 CVE-2021-37956 Use After Free vulnerability in multiple products
Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8
2021-10-08 CVE-2021-37957 Use After Free vulnerability in multiple products
Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8
2021-10-08 CVE-2021-37959 Use After Free vulnerability in multiple products
Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8
2021-10-08 CVE-2021-37961 Use After Free vulnerability in multiple products
Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8
2021-10-08 CVE-2021-37962 Use After Free vulnerability in multiple products
Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8