CVE-2023-2462
- EPSS 0.32%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:39
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-2463
- EPSS 0.32%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:40
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-2464
- EPSS 0.19%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:40
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium securi...
CVE-2023-2465
- EPSS 0.27%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:40
Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-2466
- EPSS 0.32%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:40
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-2467
- EPSS 0.03%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:40
Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-2468
- EPSS 0.32%
- Published 03.05.2023 00:15:09
- Last modified 21.11.2024 07:58:40
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-2459
- EPSS 0.04%
- Published 03.05.2023 00:15:08
- Last modified 21.11.2024 07:58:39
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-0458
- EPSS 0.1%
- Published 26.04.2023 19:15:08
- Last modified 21.11.2024 07:37:13
A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend ...
CVE-2023-0045
- EPSS 0.25%
- Published 25.04.2023 23:15:09
- Last modified 13.02.2025 17:15:52
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctr...