CVE-2022-3040
- EPSS 0.47%
- Published 26.09.2022 16:15:11
- Last modified 21.05.2025 19:15:57
Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-2852
- EPSS 1.16%
- Published 26.09.2022 16:15:10
- Last modified 22.05.2025 15:15:54
Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-2853
- EPSS 1.6%
- Published 26.09.2022 16:15:10
- Last modified 22.05.2025 15:15:55
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-2613
- EPSS 0.65%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:21
Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVE-2022-2614
- EPSS 0.65%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:21
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-2615
- EPSS 0.44%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:21
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2022-2616
- EPSS 0.27%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:21
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the Omnibox (URL bar) via a crafted Chrome Extension.
CVE-2022-2617
- EPSS 0.18%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:21
Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
CVE-2022-2618
- EPSS 0.2%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:22
Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .
CVE-2022-2619
- EPSS 0.27%
- Published 12.08.2022 20:15:09
- Last modified 21.11.2024 07:01:22
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.