CVE-2023-6511
- EPSS 0.2%
- Published 06.12.2023 02:15:07
- Last modified 21.11.2024 08:44:00
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-6512
- EPSS 0.6%
- Published 06.12.2023 02:15:07
- Last modified 28.05.2025 16:15:32
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-40462
- EPSS 0.01%
- Published 04.12.2023 23:15:25
- Last modified 13.02.2025 17:17:04
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEM...
CVE-2023-42916
- EPSS 0.04%
- Published 30.11.2023 23:15:07
- Last modified 29.11.2024 15:03:51
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that th...
CVE-2023-42917
- EPSS 0.06%
- Published 30.11.2023 23:15:07
- Last modified 10.02.2025 17:55:21
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report th...
CVE-2023-6345
- EPSS 0.26%
- Published 29.11.2023 12:15:07
- Last modified 10.03.2025 20:33:27
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CVE-2023-6346
- EPSS 0.45%
- Published 29.11.2023 12:15:07
- Last modified 21.11.2024 08:43:40
Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6347
- EPSS 0.46%
- Published 29.11.2023 12:15:07
- Last modified 05.06.2025 14:15:30
Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6348
- EPSS 0.87%
- Published 29.11.2023 12:15:07
- Last modified 21.11.2024 08:43:40
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6350
- EPSS 1.2%
- Published 29.11.2023 12:15:07
- Last modified 21.11.2024 08:43:40
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)