Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-27 CVE-2017-5062 Use After Free vulnerability in multiple products
A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to potentially perform out of bounds memory access via a crafted Chrome extension.
network
low complexity
google redhat CWE-416
8.8
2017-10-27 CVE-2017-5059 Type Confusion vulnerability in multiple products
Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to potentially obtain code execution via a crafted HTML page.
network
low complexity
google redhat CWE-843
8.8
2017-10-27 CVE-2017-5058 Use After Free vulnerability in Google Chrome
A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2017-10-27 CVE-2017-5057 Type Confusion vulnerability in multiple products
Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
network
low complexity
google redhat CWE-843
8.8
2017-10-27 CVE-2017-5056 Use After Free vulnerability in multiple products
A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
network
low complexity
google redhat CWE-416
8.8
2017-10-27 CVE-2017-5055 Use After Free vulnerability in Google Chrome
A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2017-10-27 CVE-2017-5054 Out-of-bounds Read vulnerability in multiple products
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.
network
low complexity
google redhat CWE-125
8.8
2017-10-27 CVE-2017-5052 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers improper casting.
network
low complexity
google redhat CWE-119
8.8
2017-10-18 CVE-2014-3164 NULL Pointer Dereference vulnerability in Google Android
cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers to cause a denial of service (NULL pointer dereference, or out-of-bounds write) via vectors related to binder passed lengths.
network
low complexity
google CWE-476
7.5
2017-10-10 CVE-2017-9683 Integer Overflow or Wraparound vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a meta image, an integer overflow can occur, if user-defined image offset and size values are too large.
local
low complexity
google CWE-190
7.2