CVE-2021-37997
- EPSS 0.86%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:13
Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37998
- EPSS 0.89%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:13
Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37999
- EPSS 0.54%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:14
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.
CVE-2021-38000
- EPSS 3.2%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 24.10.2025 13:55:42
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
CVE-2021-38001
- EPSS 30.05%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:14
Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-38002
- EPSS 0.83%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:14
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-38003
- EPSS 72.28%
- Veröffentlicht 23.11.2021 22:15:07
- Zuletzt bearbeitet 24.10.2025 14:10:04
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-41281
- EPSS 0.55%
- Veröffentlicht 23.11.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:25:57
Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authenti...
CVE-2021-3672
- EPSS 0.09%
- Veröffentlicht 23.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:07
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulner...
CVE-2021-44143
- EPSS 7.78%
- Veröffentlicht 22.11.2021 20:15:18
- Zuletzt bearbeitet 21.11.2024 06:30:25
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, ...