Summary
Detail | |||
---|---|---|---|
Vendor | First view | 2018-11-14 | |
Product | Chrome | Last view | 2023-05-30 |
Version | 69.0.3493.2 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:google:chrome |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.3 | 2023-05-30 | CVE-2023-2941 | Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the UI via a crafted Chrome Extension. (Chromium security severity: Low) |
6.5 | 2023-05-30 | CVE-2023-2940 | Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
7.8 | 2023-05-30 | CVE-2023-2939 | Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) |
4.3 | 2023-05-30 | CVE-2023-2938 | Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) |
4.3 | 2023-05-30 | CVE-2023-2937 | Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) |
8.8 | 2023-05-30 | CVE-2023-2936 | Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2935 | Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2934 | Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2933 | Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2932 | Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2931 | Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2930 | Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-30 | CVE-2023-2929 | Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-16 | CVE-2023-2726 | Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium) |
8.8 | 2023-05-16 | CVE-2023-2725 | Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-16 | CVE-2023-2724 | Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-16 | CVE-2023-2723 | Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-16 | CVE-2023-2722 | Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 | 2023-05-16 | CVE-2023-2721 | Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) |
8.8 | 2023-05-12 | CVE-2023-2458 | Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High) |
8.8 | 2023-05-12 | CVE-2023-2457 | Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High) |
4.3 | 2023-05-03 | CVE-2023-2468 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low) |
4.3 | 2023-05-03 | CVE-2023-2467 | Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low) |
4.3 | 2023-05-03 | CVE-2023-2466 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low) |
4.3 | 2023-05-03 | CVE-2023-2465 | Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
42% (478) | CWE-416 | Use After Free |
24% (281) | CWE-787 | Out-of-bounds Write |
7% (80) | CWE-20 | Improper Input Validation |
3% (40) | CWE-125 | Out-of-bounds Read |
2% (31) | CWE-190 | Integer Overflow or Wraparound |
2% (24) | CWE-346 | Origin Validation Error |
2% (24) | CWE-276 | Incorrect Default Permissions |
2% (23) | CWE-668 | Exposure of Resource to Wrong Sphere |
1% (16) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
1% (13) | CWE-290 | Authentication Bypass by Spoofing |
1% (12) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
0% (11) | CWE-362 | Race Condition |
0% (10) | CWE-732 | Incorrect Permission Assignment for Critical Resource |
0% (9) | CWE-203 | Information Exposure Through Discrepancy |
0% (9) | CWE-200 | Information Exposure |
0% (8) | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
0% (6) | CWE-269 | Improper Privilege Management |
0% (4) | CWE-285 | Improper Access Control (Authorization) |
0% (4) | CWE-281 | Improper Preservation of Permissions |
0% (4) | CWE-209 | Information Exposure Through an Error Message |
0% (4) | CWE-74 | Failure to Sanitize Data into a Different Plane ('Injection') |
0% (3) | CWE-415 | Double Free |
0% (3) | CWE-312 | Cleartext Storage of Sensitive Information |
0% (2) | CWE-755 | Improper Handling of Exceptional Conditions |
0% (2) | CWE-754 | Improper Check for Unusual or Exceptional Conditions |
SAINT Exploits
Description | Link |
---|---|
Google Chrome SimplifiedLowering bug | More info here |
Snort® IPS/IDS
Date | Description |
---|---|
2020-12-23 | Google Chrome Blink Renderer MediaElementEventListener memory corruption attempt RuleID : 56438 - Type : BROWSER-CHROME - Revision : 1 |
2020-12-23 | Google Chrome Blink Renderer MediaElementEventListener memory corruption attempt RuleID : 56437 - Type : BROWSER-CHROME - Revision : 1 |
2020-12-01 | Google Chrome PNG in TTF parsing heap overflow attempt RuleID : 56133 - Type : BROWSER-CHROME - Revision : 2 |
2020-12-01 | Google Chrome PNG in TTF parsing heap overflow attempt RuleID : 56132 - Type : BROWSER-CHROME - Revision : 2 |
2020-12-01 | Google Chrome PNG in TTF parsing heap overflow attempt RuleID : 56131 - Type : BROWSER-CHROME - Revision : 2 |
2020-12-01 | Google Chrome PNG in TTF parsing heap overflow attempt RuleID : 56130 - Type : BROWSER-CHROME - Revision : 2 |
2020-10-27 | Google Chrome AudioArray memory corruption attempt RuleID : 55810 - Type : BROWSER-CHROME - Revision : 1 |
2020-10-27 | Google Chrome AudioArray memory corruption attempt RuleID : 55809 - Type : BROWSER-CHROME - Revision : 1 |
2020-09-02 | Google Chrome blink webaudio module use after free attempt RuleID : 54625 - Type : BROWSER-CHROME - Revision : 1 |
2020-09-02 | Google Chrome blink webaudio module use after free attempt RuleID : 54624 - Type : BROWSER-CHROME - Revision : 1 |
2020-09-02 | Google Chrome ReadableStream out of bounds read attempt RuleID : 54623 - Type : BROWSER-CHROME - Revision : 1 |
2020-09-02 | Google Chrome ReadableStream out of bounds read attempt RuleID : 54622 - Type : BROWSER-CHROME - Revision : 1 |
2020-08-11 | Google Chrome Blink use-after-free attempt RuleID : 54498 - Type : BROWSER-CHROME - Revision : 1 |
2020-08-11 | Google Chrome Blink use-after-free attempt RuleID : 54497 - Type : BROWSER-CHROME - Revision : 1 |
2020-06-11 | Google Chromium for Android AddInterface use after free attempt RuleID : 53943 - Type : BROWSER-CHROME - Revision : 1 |
2020-06-11 | Google Chromium for Android AddInterface use after free attempt RuleID : 53942 - Type : BROWSER-CHROME - Revision : 1 |
2020-06-10 | Google Chromium ImageCapture use after free attempt RuleID : 53845 - Type : BROWSER-CHROME - Revision : 1 |
2020-06-10 | Google Chromium ImageCapture use after free attempt RuleID : 53844 - Type : BROWSER-CHROME - Revision : 1 |
2020-06-04 | Chromium use after free exploitation attempt RuleID : 53836 - Type : INDICATOR-COMPROMISE - Revision : 1 |
2020-06-04 | Chromium use after free exploitation attempt RuleID : 53835 - Type : INDICATOR-COMPROMISE - Revision : 1 |
2020-05-27 | Google Chrome ObjectCreate type confusion attempt RuleID : 53754 - Type : BROWSER-CHROME - Revision : 1 |
2020-05-27 | Google Chrome ObjectCreate type confusion attempt RuleID : 53753 - Type : BROWSER-CHROME - Revision : 1 |
2020-05-27 | Google Chrome ObjectCreate type confusion attempt RuleID : 53752 - Type : BROWSER-CHROME - Revision : 1 |
2020-05-27 | Google Chrome ObjectCreate type confusion attempt RuleID : 53751 - Type : BROWSER-CHROME - Revision : 1 |
2020-05-05 | Google Chrome desktopMediaPickerController use after free attempt RuleID : 53534 - Type : BROWSER-CHROME - Revision : 1 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2019-01-16 | Name: The remote Fedora host is missing a security update. File: fedora_2019-348547a32d.nasl - Type: ACT_GATHER_INFO |
2019-01-07 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_720590df10eb11e9b407080027ef1a23.nasl - Type: ACT_GATHER_INFO |
2019-01-07 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_546d4dd410ea11e9b407080027ef1a23.nasl - Type: ACT_GATHER_INFO |
2019-01-07 | Name: The remote Fedora host is missing a security update. File: fedora_2019-859384e002.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-13d8c35127.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-34f7f68029.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-39be36e9fc.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-8e866c5066.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-fd194a1f14.nasl - Type: ACT_GATHER_INFO |
2018-12-27 | Name: The remote CentOS host is missing a security update. File: centos_RHSA-2018-3833.nasl - Type: ACT_GATHER_INFO |
2018-12-27 | Name: The remote CentOS host is missing a security update. File: centos_RHSA-2018-3831.nasl - Type: ACT_GATHER_INFO |
2018-12-24 | Name: The remote Debian host is missing a security update. File: debian_DLA-1613.nasl - Type: ACT_GATHER_INFO |
2018-12-14 | Name: A web browser installed on the remote macOS host is affected by a use after f... File: macosx_google_chrome_71_0_3578_98.nasl - Type: ACT_GATHER_INFO |
2018-12-14 | Name: A web browser installed on the remote Windows host is affected by a use after... File: google_chrome_71_0_3578_98.nasl - Type: ACT_GATHER_INFO |
2018-12-14 | Name: The remote Debian host is missing a security update. File: debian_DLA-1605.nasl - Type: ACT_GATHER_INFO |
2018-12-13 | Name: The remote FreeBSD host is missing one or more security-related updates. File: freebsd_pkg_d10b49b28d0249e8afde0844626317af.nasl - Type: ACT_GATHER_INFO |
2018-12-13 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-4354.nasl - Type: ACT_GATHER_INFO |
2018-12-12 | Name: A web browser installed on the remote Windows host is affected by multiple vu... File: mozilla_firefox_60_4_esr.nasl - Type: ACT_GATHER_INFO |
2018-12-12 | Name: A web browser installed on the remote Windows host is affected by multiple vu... File: mozilla_firefox_64_0.nasl - Type: ACT_GATHER_INFO |
2018-12-12 | Name: A web browser installed on the remote macOS host is affected by multiple vuln... File: macosx_firefox_64_0.nasl - Type: ACT_GATHER_INFO |
2018-12-12 | Name: A web browser installed on the remote macOS host is affected by multiple vuln... File: macosx_firefox_60_4_esr.nasl - Type: ACT_GATHER_INFO |
2018-12-10 | Name: A web browser installed on the remote macOS host is affected by multiple vuln... File: macosx_google_chrome_71_0_3578_80.nasl - Type: ACT_GATHER_INFO |
2018-12-10 | Name: A web browser installed on the remote Windows host is affected by multiple vu... File: google_chrome_71_0_3578_80.nasl - Type: ACT_GATHER_INFO |
2018-12-10 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-4352.nasl - Type: ACT_GATHER_INFO |
2018-11-26 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201811-10.nasl - Type: ACT_GATHER_INFO |