Google

Chrome

3758 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.56%
  • Veröffentlicht 09.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:02

Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • EPSS 19.03%
  • Veröffentlicht 09.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:02

A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

  • EPSS 0.15%
  • Veröffentlicht 09.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:02

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • EPSS 0.57%
  • Veröffentlicht 09.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:03

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

  • EPSS 0.38%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 02:43:56

Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

  • EPSS 52.74%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:01:34

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • EPSS 1.18%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • EPSS 0.38%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had...

  • EPSS 0.09%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

  • EPSS 0.01%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privilege escalation in Crash Reporting in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to perform privile...