Vulnerabilities > Google > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-27 | CVE-2018-6131 | Out-of-bounds Write vulnerability in Google Chrome Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2019-06-27 | CVE-2018-6121 | Improper Input Validation vulnerability in Google Chrome Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a crafted HTML page. | 8.8 |
2019-06-27 | CVE-2018-6118 | Use After Free vulnerability in Google Chrome A double-eviction in the Incognito mode cache that lead to a user-after-free in cache in Google Chrome prior to 66.0.3359.139 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. | 8.8 |
2019-06-27 | CVE-2018-17479 | Use After Free vulnerability in Google Chrome Incorrect object lifetime calculations in GPU code in Google Chrome prior to 70.0.3538.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2019-06-27 | CVE-2018-17478 | Improper Validation of Array Index vulnerability in Google Chrome Incorrect array position calculations in V8 in Google Chrome prior to 70.0.3538.102 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. | 8.8 |
2019-06-27 | CVE-2018-16070 | Integer Overflow or Wraparound vulnerability in Google Chrome Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2019-06-19 | CVE-2019-2025 | Improper Locking vulnerability in Google Android In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. | 7.8 |
2019-06-19 | CVE-2019-2024 | Use After Free vulnerability in Google Android In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. | 7.8 |
2019-06-19 | CVE-2019-2023 | Incorrect Permission Assignment for Critical Resource vulnerability in Google Android 8.0/8.1/9.0 In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. | 7.8 |
2019-06-19 | CVE-2019-2018 | Improper Authentication vulnerability in Google Android 8.1/9.0 In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. | 8.8 |