Filtered by vendor Google
Subscribe
Total
10294 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-1401 | 2 Google, Intsig | 2 Android, Camscanner | 2012-03-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in the CamScanner (com.intsig.camscanner) application 1.2.2.20110823 and 1.3.2.20120116 for Android has unknown impact and attack vectors. | |||||
CVE-2009-1754 | 1 Google | 1 Android | 2012-02-28 | 4.3 MEDIUM | N/A |
The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application. | |||||
CVE-2011-4864 | 2 Google, Tencent | 2 Android, Mobileqq | 2012-02-28 | 5.8 MEDIUM | N/A |
The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application. | |||||
CVE-2011-4865 | 2 Google, Tencent | 3 Android, Microblogpad, Wblog | 2012-02-28 | 5.8 MEDIUM | N/A |
The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application. | |||||
CVE-2011-3874 | 1 Google | 1 Android | 2012-02-05 | 9.3 HIGH | N/A |
Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as demonstrated by zergRush to trigger a use-after-free error. | |||||
CVE-2011-4276 | 1 Google | 1 Android | 2012-01-25 | 4.3 MEDIUM | N/A |
The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer. | |||||
CVE-2011-2170 | 1 Google | 1 Chrome Os | 2012-01-17 | 4.4 MEDIUM | N/A |
Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors. | |||||
CVE-2011-2171 | 1 Google | 1 Chrome Os | 2012-01-17 | 10.0 HIGH | N/A |
Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has unknown impact and attack vectors. | |||||
CVE-2010-4804 | 1 Google | 1 Android | 2011-10-26 | 4.3 MEDIUM | N/A |
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/. | |||||
CVE-2011-1840 | 2 Google, Martinicreations | 2 Android, Passmanlite Password Manager | 2011-09-21 | 2.1 LOW | N/A |
The MartiniCreations PassmanLite Password Manager application before 1.48 for Android stores the master password and unspecified other account information in cleartext, which allows local users to obtain sensitive information by leveraging shell access. | |||||
CVE-2011-1001 | 1 Google | 1 Android Sdk | 2011-09-06 | 4.3 MEDIUM | N/A |
dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method. | |||||
CVE-2010-0316 | 1 Google | 1 Google Sketchup | 2011-08-07 | 9.3 HIGH | N/A |
Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a crafted SKP file. | |||||
CVE-2011-1339 | 1 Google | 1 Search Appliance | 2011-07-31 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Google Search Appliance before 5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-2344 | 1 Google | 1 Android | 2011-07-08 | 10.0 HIGH | N/A |
Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com. | |||||
CVE-2011-2169 | 1 Google | 1 Chrome Os | 2011-05-24 | 7.2 HIGH | N/A |
Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing commands in it. | |||||
CVE-2011-1149 | 1 Google | 1 Android | 2011-04-22 | 7.2 HIGH | N/A |
Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK. | |||||
CVE-2010-4212 | 2 Google, Usaa | 2 Android, Usaa | 2010-12-21 | 1.9 LOW | N/A |
The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data. | |||||
CVE-2010-4213 | 2 Bankofamerica, Google | 2 Bank Of America, Android | 2010-11-08 | 4.3 MEDIUM | N/A |
The Bank of America application 2.12 for Android stores a security question's answer in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data. | |||||
CVE-2010-4214 | 2 Google, Wellsfargo | 2 Android, Wells Fargo Mobile | 2010-11-08 | 4.3 MEDIUM | N/A |
The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data. | |||||
CVE-2009-3932 | 1 Google | 1 Chrome | 2009-11-12 | 9.3 HIGH | N/A |
The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting "SQL metadata into a bad state." |