Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-06 CVE-2021-30162 Unspecified vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software.
local
low complexity
google
7.1
2021-03-31 CVE-2021-22538 Incorrect Default Permissions vulnerability in Google Exposure Notifications Verification Server
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own.
network
low complexity
google CWE-276
8.8
2021-03-16 CVE-2021-21193 Use After Free vulnerability in multiple products
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8
2021-03-16 CVE-2021-21192 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-787
8.8
2021-03-16 CVE-2021-21191 Use After Free vulnerability in multiple products
Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-416
8.8
2021-03-10 CVE-2021-0465 Out-of-bounds Write vulnerability in Google Android
In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8
2021-03-10 CVE-2021-0464 Out-of-bounds Write vulnerability in Google Android
In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2021-03-10 CVE-2021-0389 Missing Authorization vulnerability in Google Android 11.0
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0388 Missing Authorization vulnerability in Google Android 11.0
In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0386 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value.
local
low complexity
google CWE-1021
7.8