
CVE-2023-4907 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4907
12 Sep 2023 — Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low) La implementación inapropiada en Intents en Google Chrome en Android anterior a 117.0.5938.62 permitió a un atacante remoto ofuscar la interfaz de usuario de seguridad a través de una página HTML manipulada. (Severidad de seguridad de Chrome: baja) Multiple vulnerabilities have been discovered in Chromium and ... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4906 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4906
12 Sep 2023 — Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) La aplicación insuficiente de políticas en Autofill en Google Chrome antes de 117.0.5938.62 permitió a un atacante remoto evitar las restricciones de Autocompletar a través de una página HTML manipulada. (Severidad de seguridad de Chrome: baja) Multiple vulnerabilities have been discovered in Chromium and its ... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4905 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4905
12 Sep 2023 — Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium) La implementación inapropiada de Prompts en Google Chrome anterior a 117.0.5938.62 permitió a un atacante remoto falsificar la interfaz de usuario de seguridad a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Multiple vulnerabilities have been discovered in Chromium and its derivatives, ... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4904 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4904
12 Sep 2023 — Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium) La aplicación insuficiente de políticas en Downloads en Google Chrome anteriores a 117.0.5938.62 permitió a un atacante remoto eludir las restricciones de las políticas empresariales mediante una descarga manipulada. (Severidad de seguridad de Chromium: media) Multiple vulnerabilities have been dis... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4903 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4903
12 Sep 2023 — Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium) La implementación inapropiada en Custom Mobile Tabs en Google Chrome en Android anterior a 117.0.5938.62 permitió a un atacante remoto falsificar la interfaz de usuario de seguridad a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Multiple vulnerabilities have been ... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4902 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4902
12 Sep 2023 — Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada en Input en Google Chrome anterior a 117.0.5938.62 permitió a un atacante remoto falsificar la interfaz de usuario de seguridad a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the w... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4901 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4901
12 Sep 2023 — Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada en Prompts en Google Chrome anteriores a 117.0.5938.62 permitía a un atacante remoto falsificar potencialmente la interfaz de usuario de seguridad a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Multiple vulnerabilities have been discovered in Ch... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4900 – Debian Security Advisory 5499-1
https://notcve.org/view.php?id=CVE-2023-4900
12 Sep 2023 — Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium) La implementación inapropiada en Custom Tabs en Google Chrome en Android anterior a 117.0.5938.62 permitió a un atacante remoto ofuscar una solicitud de permiso a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Multiple vulnerabilities have been discovered in Ch... • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html •

CVE-2023-4863 – Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2023-4863
12 Sep 2023 — Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) El desbordamiento del búfer de memoria en libwebp en Google Chrome anterior a 116.0.5845.187 y libwebp 1.3.2 permitía a un atacante remoto realizar una escritura en memoria fuera de los límites a través de una página HTML manipulada. (Severidad de seguridad de Chromium: crítica) A heap-bas... • https://github.com/alsaeroth/CVE-2023-4863-POC • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2023-41915 – pmix: race condition allows attackers to obtain ownership of arbitrary files
https://notcve.org/view.php?id=CVE-2023-41915
09 Sep 2023 — OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. OpenPMIx PMIx antes de las versiones 4.2.6 y 5.0.x antes de 5.0.1, permite a los atacantes obtener la propiedad de archivos arbitrarios a través de una condición de ejecución durante la ejecución de código de librería con UID 0. OpenPMIx PMIx is vulnerable to a race condition during execution of library code with UID 0, which allows attac... • http://www.openwall.com/lists/oss-security/2024/07/10/3 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •