Vulnerability index

Browse CVEs

4,645 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chrome MEDIUM 5.0
CVE-2010-1992

Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remot…

No fix yet
Fix from $1,600 2010-05-20
Chrome HIGH 7.5
CVE-2010-1237

Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other imp…

Mitigation only
Fix from $1,950 2010-04-01
Chrome HIGH 9.3
CVE-2010-0657

Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a deskt…

Mitigation only
Fix from $1,950 2010-02-18
Google Sketchup HIGH 9.3
CVE-2010-0316

Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute a…

Mitigation only
Fix from $1,950 2010-01-15
Chrome HIGH 9.3
CVE-2008-6994EPSS 10%

Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted rem…

No fix yet
Fix from $1,950 2009-08-19
Chrome MEDIUM 5.0
CVE-2008-6996EPSS 6%

Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to c…

No fix yet
Fix from $1,600 2009-08-19
Android MEDIUM 5.0
CVE-2009-2656

Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network…

No fix yet
Fix from $1,600 2009-08-03
Chrome MEDIUM 5.0
CVE-2009-2578

Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the …

Mitigation only
Fix from $1,600 2009-07-22
Android MEDIUM 6.9
CVE-2009-2348

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_R…

Mitigation only
Fix from $1,600 2009-07-17
Chrome HIGH 9.3
CVE-2009-1598

Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PD…

No fix yet
Fix from $1,950 2009-05-11
Chrome MEDIUM 5.0
CVE-2009-1514

Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement …

No fix yet
Fix from $1,600 2009-05-04
Chrome MEDIUM 6.8
CVE-2008-5749

Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --render…

No fix yet
Fix from $1,600 2008-12-29
Google Apps HIGH 7.5
CVE-2008-3891

The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors…

Mitigation only
Fix from $1,950 2008-09-03
Android Sdk HIGH 7.5
CVE-2008-0986

Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote at…

No fix yet
Fix from $1,950 2008-03-06
Toolbar MEDIUM 6.8
CVE-2007-6536

The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy conside…

No fix yet
Fix from $1,600 2007-12-27
Kml MEDIUM 5.0
CVE-2007-6212

Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer para…

No fix yet
Fix from $1,600 2007-12-04
Picasa MEDIUM 5.0
CVE-2007-4847

Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information…

No fix yet
Fix from $1,600 2007-09-12
Picasa HIGH 7.5
CVE-2007-4823

Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.

No fix yet
Fix from $1,950 2007-09-11
Picasa MEDIUM 6.8
CVE-2007-4824

Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is ba…

No fix yet
Fix from $1,600 2007-09-11
Custom Search Engine MEDIUM 6.1
CVE-2007-3484

Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2007-06-28
Desktop HIGH 9.3
CVE-2007-3150

Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.goog…

No fix yet
Fix from $1,950 2007-06-11
Web Toolkit MEDIUM 5.0
CVE-2007-2378

The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows r…

Mitigation only
Fix from $1,600 2007-04-30
Earth HIGH 7.1
CVE-2006-7157EPSS 7%

Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file wit…

No fix yet
Fix from $1,950 2007-03-07
Desktop HIGH 7.6
CVE-2007-1085EPSS 11%

Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HT…

No fix yet
Fix from $1,950 2007-02-23
Talk MEDIUM 5.4
CVE-2005-3899

The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's…

Mitigation only
Fix from $1,600 2005-11-29