Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-06 CVE-2023-32834 Type Confusion vulnerability in Google Android 11.0/12.0/13.0
In secmem, there is a possible memory corruption due to type confusion.
local
low complexity
google CWE-843
6.7
2023-11-06 CVE-2023-32835 Type Confusion vulnerability in Google Android 11.0/12.0/13.0
In keyinstall, there is a possible memory corruption due to type confusion.
local
low complexity
google CWE-843
6.7
2023-11-06 CVE-2023-32836 Out-of-bounds Write vulnerability in Google Android 11.0/12.0/13.0
In display, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-787
6.7
2023-11-06 CVE-2023-32838 Out-of-bounds Write vulnerability in Google Android 11.0/12.0
In dpe, there is a possible out of bounds write due to a missing valid range checking.
local
low complexity
google CWE-787
6.7
2023-11-06 CVE-2023-32839 Out-of-bounds Write vulnerability in Google Android 11.0/12.0
In dpe, there is a possible out of bounds write due to a missing valid range checking.
local
low complexity
google CWE-787
6.7
2023-11-01 CVE-2023-5480 Cross-site Scripting vulnerability in multiple products
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file.
network
low complexity
google debian fedoraproject CWE-79
6.1
2023-11-01 CVE-2023-5850 Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name.
network
low complexity
google debian fedoraproject
4.3
2023-11-01 CVE-2023-5851 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-346
4.3
2023-11-01 CVE-2023-5853 Origin Validation Error vulnerability in multiple products
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-346
4.3
2023-11-01 CVE-2023-5858 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-346
4.3