Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-9506 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation.
8.1
2019-08-05 CVE-2019-3800 Information Exposure vulnerability in multiple products
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag.
7.8
2019-07-08 CVE-2019-2116 Out-of-bounds Read vulnerability in Google Android
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2019-07-08 CVE-2019-2112 Use After Free vulnerability in Google Android 8.0/8.1/9.0
In several functions of alarm.cc, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2019-07-08 CVE-2019-2109 Out-of-bounds Write vulnerability in Google Android
In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check.
network
low complexity
google CWE-787
8.8
2019-07-08 CVE-2019-2107 Out-of-bounds Write vulnerability in Google Android
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2019-07-08 CVE-2019-2106 Out-of-bounds Write vulnerability in Google Android
In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2019-07-08 CVE-2019-2105 Use of Uninitialized Resource vulnerability in Google Android
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data.
network
low complexity
google CWE-908
8.8
2019-06-27 CVE-2019-5836 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-787
8.8
2019-06-27 CVE-2019-5831 Out-of-bounds Write vulnerability in multiple products
Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-787
8.8