Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-17 CVE-2019-20774 Unspecified vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software.
local
low complexity
google
5.5
2020-04-13 CVE-2020-6456 Incorrect Default Permissions vulnerability in multiple products
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
network
low complexity
google debian fedoraproject opensuse CWE-276
6.5
2020-04-13 CVE-2020-6446 Incorrect Default Permissions vulnerability in multiple products
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-276
6.5
2020-04-13 CVE-2020-6445 Incorrect Default Permissions vulnerability in multiple products
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-276
6.5
2020-04-13 CVE-2020-6444 Use of Uninitialized Resource vulnerability in multiple products
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject debian opensuse CWE-908
6.3
2020-04-13 CVE-2020-6442 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-668
4.3
2020-04-13 CVE-2020-6441 Incorrect Default Permissions vulnerability in multiple products
Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-276
4.3
2020-04-13 CVE-2020-6440 Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
network
low complexity
google debian fedoraproject opensuse
4.3
2020-04-13 CVE-2020-6438 Information Exposure Through an Error Message vulnerability in multiple products
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
network
low complexity
google debian fedoraproject opensuse CWE-209
4.3
2020-04-13 CVE-2020-6437 Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
network
low complexity
google debian fedoraproject opensuse
4.3