CVE-2021-30511
- EPSS 0.32%
- Veröffentlicht 04.06.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:04:04
Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
CVE-2021-30512
- EPSS 0.67%
- Veröffentlicht 04.06.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:04:04
Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30513
- EPSS 1.09%
- Veröffentlicht 04.06.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:04:04
Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30514
- EPSS 0.74%
- Veröffentlicht 04.06.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:04:04
Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30515
- EPSS 0.49%
- Veröffentlicht 04.06.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:04:04
Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-28091
- EPSS 0.51%
- Veröffentlicht 04.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:59:04
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
CVE-2021-30475
- EPSS 0.21%
- Veröffentlicht 04.06.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:03:59
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
CVE-2021-3565
- EPSS 0.12%
- Veröffentlicht 04.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:51
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat f...
CVE-2021-32625
- EPSS 1.57%
- Veröffentlicht 02.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:24
Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the heap and pot...
CVE-2021-25287
- EPSS 0.34%
- Veröffentlicht 02.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:40
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.