Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-08 CVE-2021-30632 Out-of-bounds Write vulnerability in multiple products
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-787
8.8
2021-10-06 CVE-2021-25467 Classic Buffer Overflow vulnerability in Google Android 11.0
Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.
local
low complexity
google CWE-120
7.2
2021-10-06 CVE-2021-25475 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
local
low complexity
google CWE-787
7.2
2021-10-04 CVE-2021-22557 OS Command Injection vulnerability in Google SLO Generator
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator.
local
low complexity
google CWE-78
7.8
2021-09-21 CVE-2021-0869 Out-of-bounds Write vulnerability in Google Android
In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check.
network
low complexity
google CWE-787
7.5
2021-09-09 CVE-2021-25449 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.
network
low complexity
google CWE-119
7.5
2021-08-26 CVE-2021-30590 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-787
8.8
2021-08-26 CVE-2021-30591 Use After Free vulnerability in multiple products
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
8.8
2021-08-26 CVE-2021-30592 Out-of-bounds Write vulnerability in multiple products
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
network
low complexity
google fedoraproject CWE-787
8.8
2021-08-26 CVE-2021-30593 Out-of-bounds Read vulnerability in multiple products
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
network
low complexity
google fedoraproject CWE-125
8.1