|
195491
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21113
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195492
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21112
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195493
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-21111
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195494
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21110
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195495
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21109
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195496
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21108
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195497
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft…
|
CWE-416
Use After Free
|
CVE-2021-21107
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195498
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21106
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195499
|
5.5 |
MEDIUM
Local
|
courtbouillon
|
cairosvg
|
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When process…
|
-
|
CVE-2021-21236
|
2024-11-21 14:47 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195500
|
6.5 |
MEDIUM
Network
|
kamadak-exif_project
|
kamadak-exif
|
kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. Specifically, reader::read_from_container can caus…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-21235
|
2024-11-21 14:47 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|