Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2013-11-19 CVE-2013-6631 Use After Free Remote Code Execution vulnerability in Google Chrome
Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger the absence of certain statistics initialization, leading to the skipping of a required DeRegisterExternalTransport call.
network
low complexity
google
7.5
2013-11-13 CVE-2013-6624 Resource Management Errors vulnerability in Google Chrome
Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the string values of id attributes.
network
low complexity
google CWE-399
7.5
2013-11-13 CVE-2013-6621 Resource Management Errors vulnerability in multiple products
Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.
network
low complexity
opensuse google debian CWE-399
7.5
2013-05-29 CVE-2013-3666 Permissions, Privileges, and Access Controls vulnerability in multiple products
The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB Debugging mode, using Android Debug Bridge (adb) to establish a USB connection, dialing 3845#*973#, modifying the WLAN Test Wi-Fi Ping Test/User Command tcpdump command string, and pressing the CANCEL button.
local
low complexity
google lg CWE-264
7.2
2013-02-23 CVE-2013-2268 Security vulnerability in WebKit MathML Library
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."
network
low complexity
google linux microsoft apple
7.5
2013-02-05 CVE-2011-1350 Information Exposure vulnerability in Google Android
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.
network
google CWE-200
7.1
2012-09-13 CVE-2012-4908 Permissions, Privileges, and Access Controls vulnerability in Google Chrome
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink.
network
low complexity
google CWE-264
7.5
2012-08-26 CVE-2012-3485 Improper Input Validation vulnerability in Google Tunnelblick
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.
local
low complexity
google CWE-20
7.2
2012-08-26 CVE-2012-3484 Permissions, Privileges, and Access Controls vulnerability in Google Tunnelblick
Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, which allows local users to bypass intended access restrictions and gain privileges via a (1) user-mountable image or (2) network share.
local
low complexity
google CWE-264
7.2
2012-06-27 CVE-2012-2764 Unspecified vulnerability in Google Chrome
Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.
local
low complexity
google microsoft
7.2