CVE-2024-3170
- EPSS 0.74%
- Veröffentlicht 16.07.2024 23:15:23
- Zuletzt bearbeitet 21.11.2024 09:29:03
Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-3171
- EPSS 1.09%
- Veröffentlicht 16.07.2024 23:15:23
- Zuletzt bearbeitet 21.11.2024 09:29:04
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Med...
CVE-2024-3172
- EPSS 0.77%
- Veröffentlicht 16.07.2024 23:15:23
- Zuletzt bearbeitet 18.03.2025 14:15:39
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2023-4860
- EPSS 0.35%
- Veröffentlicht 16.07.2024 23:15:11
- Zuletzt bearbeitet 26.12.2024 15:43:44
Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2023-7010
- EPSS 0.48%
- Veröffentlicht 16.07.2024 23:15:11
- Zuletzt bearbeitet 26.12.2024 15:41:50
Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-7011
- EPSS 0.11%
- Veröffentlicht 16.07.2024 23:15:11
- Zuletzt bearbeitet 26.12.2024 15:43:13
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-7012
- EPSS 0.06%
- Veröffentlicht 16.07.2024 23:15:11
- Zuletzt bearbeitet 26.12.2024 15:43:32
Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: ...
CVE-2023-7013
- EPSS 0.12%
- Veröffentlicht 16.07.2024 23:15:11
- Zuletzt bearbeitet 25.11.2024 19:15:07
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVE-2019-25154
- EPSS 0.36%
- Veröffentlicht 16.07.2024 23:15:10
- Zuletzt bearbeitet 21.11.2024 16:15:18
Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2020-36765
- EPSS 0.1%
- Veröffentlicht 16.07.2024 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:30:15
Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)