CVE-2021-37959
- EPSS 0.1%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:07
Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37961
- EPSS 0.64%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:08
Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37962
- EPSS 0.59%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:08
Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37963
- EPSS 0.03%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:08
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVE-2021-37964
- EPSS 0.35%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:08
Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.
CVE-2021-37965
- EPSS 0.22%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:08
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-37966
- EPSS 0.27%
- Published 08.10.2021 22:15:07
- Last modified 21.11.2024 06:16:08
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-41133
- EPSS 0.06%
- Published 08.10.2021 14:15:08
- Last modified 21.11.2024 06:25:33
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse ...
CVE-2021-22930
- EPSS 0.35%
- Published 07.10.2021 14:15:08
- Last modified 21.11.2024 05:50:56
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
CVE-2021-41125
- EPSS 0.21%
- Published 06.10.2021 18:15:10
- Last modified 21.11.2024 06:25:31
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. ...