Vulnerabilities > Google > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-02-12 | CVE-2017-13235 | NULL Pointer Dereference vulnerability in Google Android A other vulnerability in the Android media framework (n/a). | 6.5 |
2018-02-12 | CVE-2017-13234 | Missing Release of Resource after Effective Lifetime vulnerability in Google Android In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. | 6.5 |
2018-02-12 | CVE-2017-13233 | Resource Exhaustion vulnerability in Google Android In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. | 6.5 |
2018-02-07 | CVE-2017-5124 | Cross-site Scripting vulnerability in multiple products Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page. | 6.1 |
2018-02-07 | CVE-2017-15395 | Use After Free vulnerability in multiple products A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference. | 6.5 |
2018-02-07 | CVE-2017-15394 | Improper Input Validation vulnerability in multiple products Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension. | 6.5 |
2018-02-07 | CVE-2017-15392 | Improper Input Validation vulnerability in multiple products Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration. | 4.3 |
2018-02-07 | CVE-2017-15391 | Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page. | 6.5 |
2018-02-07 | CVE-2017-15390 | Improper Input Validation vulnerability in multiple products Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. | 6.5 |
2018-02-07 | CVE-2017-15389 | Improper Input Validation vulnerability in multiple products An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 6.5 |