CVE-2021-45463
- EPSS 1.81%
- Veröffentlicht 23.12.2021 06:15:06
- Zuletzt bearbeitet 03.11.2025 18:15:37
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. N...
CVE-2021-4062
- EPSS 2.42%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:49
Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4063
- EPSS 1.38%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:49
Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4064
- EPSS 0.97%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:49
Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4065
- EPSS 1.17%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:50
Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4066
- EPSS 1.88%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:50
Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4067
- EPSS 1.38%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:50
Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4068
- EPSS 1.05%
- Veröffentlicht 23.12.2021 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:36:50
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-38009
- EPSS 1.14%
- Veröffentlicht 23.12.2021 01:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:15
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-38010
- EPSS 0.36%
- Veröffentlicht 23.12.2021 01:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:16
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.