Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-28 CVE-2023-20944 Deserialization of Untrusted Data vulnerability in Google Android
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization.
local
low complexity
google CWE-502
7.8
2023-02-28 CVE-2023-20945 Out-of-bounds Write vulnerability in Google Android 10.0
In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2023-02-28 CVE-2023-20948 Out-of-bounds Read vulnerability in Google Android 12.0/12.1/13.0
In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow.
network
low complexity
google CWE-125
7.5
2023-02-22 CVE-2023-0927 Use After Free vulnerability in Google Chrome
Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0928 Use After Free vulnerability in Google Chrome
Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0929 Use After Free vulnerability in Google Chrome
Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0930 Out-of-bounds Write vulnerability in Google Chrome
Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-787
8.8
2023-02-22 CVE-2023-0931 Use After Free vulnerability in Google Chrome
Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0932 Use After Free vulnerability in Google Chrome
Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2023-02-22 CVE-2023-0933 Integer Overflow or Wraparound vulnerability in Google Chrome
Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
network
low complexity
google CWE-190
8.8