CVE-2021-42260
- EPSS 0.97%
- Veröffentlicht 11.10.2021 20:15:07
- Zuletzt bearbeitet 04.11.2025 19:15:40
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
CVE-2021-25633
- EPSS 0.53%
- Veröffentlicht 11.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:11
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulner...
CVE-2021-37967
- EPSS 0.7%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:09
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
CVE-2021-37968
- EPSS 0.45%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:09
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-37969
- EPSS 0.36%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:09
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
CVE-2021-37970
- EPSS 2.43%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:09
Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37971
- EPSS 0.19%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:09
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-37972
- EPSS 0.72%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:09
Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37973
- EPSS 6.66%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 24.10.2025 21:08:10
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-37974
- EPSS 1.21%
- Veröffentlicht 08.10.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:10
Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.