Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2020-09-21 CVE-2020-6550 Use After Free vulnerability in multiple products
Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-416
8.8
2020-09-21 CVE-2020-6542 Use After Free vulnerability in multiple products
Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-416
8.8
2020-09-21 CVE-2020-6541 Use After Free vulnerability in multiple products
Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-416
8.8
2020-09-18 CVE-2020-0354 Out-of-bounds Write vulnerability in Google Android 11.0
In Bluetooth, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
7.5
2020-09-17 CVE-2020-0375 Missing Authorization vulnerability in Google Android 11.0
In Telephony, there is a possible permission bypass due to a missing permission check.
local
low complexity
google CWE-862
7.2
2020-09-17 CVE-2020-0374 Incorrect Default Permissions vulnerability in Google Android 11.0
In NFC, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-276
7.2
2020-09-17 CVE-2020-0351 Improper Input Validation vulnerability in Google Android 11.0
In libstagefright, there is possible CPU exhaustion due to improper input validation.
network
google CWE-20
7.1
2020-09-17 CVE-2020-0333 Improper Input Validation vulnerability in Google Android 11.0
In UrlQuerySanitizer, there is a possible improper input validation.
network
low complexity
google CWE-20
7.5
2020-09-17 CVE-2020-0275 Incorrect Default Permissions vulnerability in Google Android 11.0
In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass.
local
low complexity
google CWE-276
7.2
2020-09-17 CVE-2020-0266 Missing Authorization vulnerability in Google Android 11.0
In factory reset protection, there is a possible FRP bypass due to a missing permission check.
local
low complexity
google CWE-862
7.2