Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-12 CVE-2022-0116 Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google fedoraproject
4.3
2022-02-12 CVE-2022-0117 Incorrect Authorization vulnerability in multiple products
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject CWE-863
6.5
2022-02-12 CVE-2022-0118 Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google fedoraproject
4.3
2022-02-12 CVE-2022-0120 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
network
low complexity
google fedoraproject CWE-346
6.5
2022-02-11 CVE-2021-0524 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-02-11 CVE-2021-39631 Unspecified vulnerability in Google Android 10.0/11.0/12.0
In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wrong security/privacy expectations due to a misleading message.
local
low complexity
google
5.5
2022-02-11 CVE-2021-39664 Out-of-bounds Read vulnerability in Google Android 12.0
In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2022-02-11 CVE-2021-39665 Out-of-bounds Write vulnerability in Google Android 12.0
In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow.
network
low complexity
google CWE-787
6.5
2022-02-11 CVE-2021-39666 Out-of-bounds Read vulnerability in Google Android 11.0/12.0
In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation.
local
low complexity
google CWE-125
5.5
2022-02-11 CVE-2021-39671 Use of Uninitialized Resource vulnerability in Google Android 12.0
In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data.
network
low complexity
google CWE-908
6.5