CVE-2025-5281
- EPSS 0.21%
- Veröffentlicht 27.05.2025 20:43:04
- Zuletzt bearbeitet 29.05.2025 15:50:25
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5283
- EPSS 0.27%
- Veröffentlicht 27.05.2025 20:43:04
- Zuletzt bearbeitet 03.11.2025 20:19:16
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5064
- EPSS 0.13%
- Veröffentlicht 27.05.2025 20:43:03
- Zuletzt bearbeitet 29.05.2025 15:51:09
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5065
- EPSS 0.12%
- Veröffentlicht 27.05.2025 20:43:03
- Zuletzt bearbeitet 29.05.2025 15:50:57
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5280
- EPSS 0.64%
- Veröffentlicht 27.05.2025 20:43:03
- Zuletzt bearbeitet 29.05.2025 15:50:31
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-5063
- EPSS 0.46%
- Veröffentlicht 27.05.2025 20:43:02
- Zuletzt bearbeitet 02.07.2025 14:15:26
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-4664
- EPSS 0.12%
- Veröffentlicht 14.05.2025 17:41:06
- Zuletzt bearbeitet 06.06.2025 01:00:02
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2025-4372
- EPSS 0.2%
- Veröffentlicht 06.05.2025 21:35:44
- Zuletzt bearbeitet 28.05.2025 20:00:04
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-4051
- EPSS 0.12%
- Veröffentlicht 05.05.2025 18:15:44
- Zuletzt bearbeitet 28.05.2025 20:08:14
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security sever...
CVE-2025-4052
- EPSS 0.19%
- Veröffentlicht 05.05.2025 18:15:44
- Zuletzt bearbeitet 28.05.2025 20:07:45
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security sever...