Google

Chrome

3866 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 09.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:02

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • EPSS 0.33%
  • Veröffentlicht 09.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:03

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

  • EPSS 0.38%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 02:43:56

Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

  • EPSS 52.74%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:01:34

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • EPSS 1.18%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • EPSS 0.38%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had...

  • EPSS 0.09%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

  • EPSS 0.01%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privilege escalation in Crash Reporting in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to perform privile...

  • EPSS 0.01%
  • Veröffentlicht 09.01.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.31...

Exploit
  • EPSS 13.22%
  • Veröffentlicht 21.12.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:17

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by l...