Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-23 CVE-2019-5787 Use After Free vulnerability in multiple products
Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google opensuse CWE-416
8.8
2019-05-08 CVE-2019-2054 In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace.
local
low complexity
google canonical
7.8
2019-05-08 CVE-2019-2052 Type Confusion vulnerability in Google Android
In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion.
network
low complexity
google CWE-843
7.5
2019-05-08 CVE-2019-2051 Out-of-bounds Read vulnerability in Google Android
In heap of spaces.h, there is a possible out of bounds read due to improper input validation.
network
low complexity
google CWE-125
7.5
2019-05-08 CVE-2019-2050 Improper Locking vulnerability in Google Android 8.0/8.1/9.0
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking.
local
low complexity
google CWE-667
7.8
2019-05-08 CVE-2019-2049 Use After Free vulnerability in Google Android 9.0
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2019-05-08 CVE-2019-2044 Out-of-bounds Write vulnerability in Google Android
In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check.
network
low complexity
google CWE-787
8.8
2019-05-08 CVE-2019-2043 Insecure Default Initialization of Resource vulnerability in Google Android
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack.
local
low complexity
google CWE-1188
7.3
2019-05-07 CVE-2018-6243 Improper Input Validation vulnerability in Google Android
NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead to Arbitrary Code Execution, Denial of Service or Escalation of Privileges.
local
low complexity
google CWE-20
7.8
2019-04-24 CVE-2018-7577 Improper Input Validation vulnerability in Google Tensorflow
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
network
low complexity
google CWE-20
8.1