Vulnerabilities
Vulnerable Software
Google:  >> Chrome Os  >> 0.10.140.0  Security Vulnerabilities
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.
CVSS Score
7.8
EPSS Score
0.001
Published
2019-10-01
Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVSS Score
9.6
EPSS Score
0.004
Published
2019-01-09
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
CVSS Score
7.3
EPSS Score
0.001
Published
2019-01-09
Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.
CVSS Score
9.8
EPSS Score
0.034
Published
2018-03-07
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.
CVSS Score
7.4
EPSS Score
0.003
Published
2018-02-07
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
CVSS Score
7.8
EPSS Score
0.004
Published
2018-02-07
Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.
CVSS Score
3.3
EPSS Score
0.0
Published
2017-10-27
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.
CVSS Score
8.8
EPSS Score
0.024
Published
2016-10-13
Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVSS Score
8.8
EPSS Score
0.006
Published
2016-09-25
CVE-2016-4171
Known exploited
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
CVSS Score
9.8
EPSS Score
0.26
Published
2016-06-16


Contact Us

Shodan ® - All rights reserved