Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-05 CVE-2021-41197 Integer Overflow or Wraparound vulnerability in Google Tensorflow
TensorFlow is an open source platform for machine learning.
local
low complexity
google CWE-190
5.5
2021-11-05 CVE-2021-41198 Integer Overflow or Wraparound vulnerability in Google Tensorflow
TensorFlow is an open source platform for machine learning.
local
low complexity
google CWE-190
5.5
2021-11-05 CVE-2021-41199 Integer Overflow or Wraparound vulnerability in Google Tensorflow
TensorFlow is an open source platform for machine learning.
local
low complexity
google CWE-190
5.5
2021-11-05 CVE-2021-41200 Reachable Assertion vulnerability in Google Tensorflow
TensorFlow is an open source platform for machine learning.
local
low complexity
google CWE-617
5.5
2021-11-05 CVE-2021-25500 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.
local
low complexity
google CWE-787
4.4
2021-11-05 CVE-2021-25502 Cleartext Storage of Sensitive Information vulnerability in Google Android
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
local
low complexity
google CWE-312
5.5
2021-11-05 CVE-2021-25503 Improper Input Validation vulnerability in Google Android
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
local
low complexity
google CWE-20
6.7
2021-11-02 CVE-2018-6125 Unspecified vulnerability in Google Chrome
Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
network
low complexity
google
6.5
2021-11-02 CVE-2020-16048 Out-of-bounds Read vulnerability in Google Angle
Out of bounds read in ANGLE allowed a remote attacker to obtain sensitive data via a crafted HTML page.
network
low complexity
google CWE-125
6.5
2021-11-02 CVE-2021-37989 Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.
network
low complexity
google debian
6.5