CVE-2021-28700
- EPSS 2.13%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:10
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond wh...
CVE-2021-40153
- EPSS 0.54%
- Veröffentlicht 27.08.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:23:40
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination dire...
CVE-2021-30591
- EPSS 0.48%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:14
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30592
- EPSS 0.23%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
CVE-2021-30593
- EPSS 0.27%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
CVE-2021-30594
- EPSS 0.31%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
CVE-2021-30596
- EPSS 0.2%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-30597
- EPSS 0.28%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
CVE-2021-30598
- EPSS 1.88%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2021-30599
- EPSS 1.91%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.