Skip to content
Noroxi

Google records

16,718 published records for vendor google.

Researcher profile

Entered KEV
113 · 0.7%
Weaponized
135 · 0.8%
Pre-auth RCE
1,845
With a fix record
41.9%
Median publish → KEV
29 days

All records

10,000+ records
  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerFeb 5, 2014

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    adobe · flash playerApr 13, 2011

  • Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a s

    HighCVSS 8.8KEVWeaponizedEPSS 85%

    google · chromeNov 14, 2018

  • Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft

    HighCVSS 8.8KEVWeaponizedEPSS 84%

    google · chromeApr 26, 2021

  • Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x

    HighCVSS 8.1KEVWeaponizedEPSS 91%

    adobe · flash playerFeb 16, 2012

  • Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 79%

    google · chromeFeb 27, 2020

  • Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.

    HighCVSS 7.8KEVWeaponizedEPSS 90%

    adobe · flash playerJan 18, 2019

  • A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.

    HighCVSS 7.8KEVWeaponizedEPSS 90%

    adobe · flash playerFeb 6, 2018

  • Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via

    HighCVSS 8.8KEVWeaponizedEPSS 70%

    google · chromeJul 27, 2022

  • Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit he

    HighCVSS 8.8KEVWeaponizedEPSS 70%

    google · chromeApr 26, 2021

  • Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on

    HighCVSS 8.8KEVWeaponizedEPSS 68%

    adobe · air sdkDec 28, 2015

  • Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 65%

    google · chromeJun 15, 2021

  • Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a craf

    HighCVSS 8.8KEVWeaponizedEPSS 63%

    google · chromeOct 8, 2021

  • A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.

    HighCVSS 7.8KEVWeaponizedEPSS 72%

    google · androidOct 11, 2019

  • Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3

    HighCVSS 8.8KEVWeaponizedEPSS 60%

    google · chromeNov 14, 2018

  • Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra

    HighCVSS 8.8KEVWeaponizedEPSS 55%

    google · chromeFeb 13, 2026

  • Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2

    HighCVSS 8.8KEVWeaponizedEPSS 55%

    adobe · flash playerFeb 10, 2016

  • Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi

    CriticalCVSS 9.6KEVWeaponizedEPSS 44%

    google · chromeNov 2, 2020

  • Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on

    HighCVSS 7.8KEVWeaponizedEPSS 64%

    adobe · flash playerMar 15, 2011

  • Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a cra

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    google · chromeNov 25, 2019

  • Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    google · chromeSep 28, 2023

  • Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    google · chromeSep 3, 2026

  • CVE-2020-16009
    79This week

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption

    HighCVSS 8.8KEVWeaponizedEPSS 48%

    google · chromeNov 2, 2020

  • CVE-2016-1646
    79This week

    The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly cons

    HighCVSS 8.8KEVWeaponizedEPSS 48%

    google · chromeMar 29, 2016