Search Results (4191 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-3169 1 Google 1 Chrome 2024-11-21 8.8 High
Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6181 1 Google 2 Chromecast, Chromecast Firmware 2024-11-21 9.8 Critical
An oversight in BCB handling of reboot reason that allows for persistent code execution
CVE-2023-48424 1 Google 2 Chromecast, Chromecast Firmware 2024-11-21 9.8 Critical
U-Boot shell vulnerability resulting in Privilege escalation in a production device
CVE-2023-48417 1 Google 2 Chromecast, Chromecast Firmware 2024-11-21 9.8 Critical
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
CVE-2023-47131 4 Google, Microsoft, Mozilla and 1 more 4 Chrome, Edge, Firefox and 1 more 2024-11-21 7.5 High
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
CVE-2023-3742 1 Google 2 Chrome, Chrome Os 2024-11-21 6.8 Medium
Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via physical access to the device. (Chromium security severity: High)
CVE-2023-3739 1 Google 2 Chrome, Chrome Os 2024-11-21 6.3 Medium
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
CVE-2023-3731 1 Google 2 Chrome, Chrome Os 2024-11-21 8.8 High
Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CVE-2023-3729 1 Google 2 Chrome, Chrome Os 2024-11-21 8.8 High
Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)
CVE-2023-3497 1 Google 2 Chrome, Chrome Os 2024-11-21 4.6 Medium
Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)
CVE-2023-2458 1 Google 2 Chrome, Chrome Os 2024-11-21 8.8 High
Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)
CVE-2023-2457 1 Google 2 Chrome, Chrome Os 2024-11-21 8.8 High
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
CVE-2023-1236 1 Google 1 Chrome 2024-11-21 4.3 Medium
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-1235 1 Google 1 Chrome 2024-11-21 6.3 Medium
Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)
CVE-2023-1234 1 Google 2 Android, Chrome 2024-11-21 4.3 Medium
Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-1233 1 Google 1 Chrome 2024-11-21 4.3 Medium
Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from API via a crafted Chrome Extension. (Chromium security severity: Low)
CVE-2023-1232 1 Google 1 Chrome 2024-11-21 4.3 Medium
Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-1231 1 Google 2 Android, Chrome 2024-11-21 4.3 Medium
Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the omnibox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-1230 1 Google 2 Android, Chrome 2024-11-21 4.3 Medium
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious WebApp to spoof the contents of the PWA installer via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-1229 1 Google 1 Chrome 2024-11-21 4.3 Medium
Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)