Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-28 CVE-2023-20940 Improper Verification of Cryptographic Signature vulnerability in Google Android 13.0
In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto.
local
low complexity
google CWE-347
7.8
2023-02-28 CVE-2023-20943 Path Traversal vulnerability in Google Android
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error.
local
low complexity
google CWE-22
7.8
2023-02-28 CVE-2023-20944 Deserialization of Untrusted Data vulnerability in Google Android
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization.
local
low complexity
google CWE-502
7.8
2023-02-28 CVE-2023-20945 Out-of-bounds Write vulnerability in Google Android 10.0
In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2023-02-28 CVE-2023-20948 Out-of-bounds Read vulnerability in Google Android 12.0/12.1/13.0
In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow.
network
low complexity
google CWE-125
7.5
2023-02-22 CVE-2023-0927 Use After Free vulnerability in Google Chrome
Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0928 Use After Free vulnerability in Google Chrome
Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0929 Use After Free vulnerability in Google Chrome
Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0930 Out-of-bounds Write vulnerability in Google Chrome
Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-787
8.8
2023-02-22 CVE-2023-0931 Use After Free vulnerability in Google Chrome
Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8