CVE-2021-21125 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21125
25 Jan 2021 — Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. Una aplicación de políticas insuficientes en File System API en Google Chrome en Windows versiones anteriores a 88.0.4324.96, permitió a un atacante remoto omitir las restricciones del sistema de archivos por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst o... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2021-21126 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21126
25 Jan 2021 — Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. Una aplicación de políticas insuficientes en extensions de Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto omitir el aislamiento del sitio por medio de una Extension de Chrome diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execu... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html • CWE-20: Improper Input Validation •
CVE-2021-21127 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21127
25 Jan 2021 — Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension. Una aplicación de políticas insuficientes en extensions de Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto omitir la política de seguridad de contenido por medio de una Extension de Chrome diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result ... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html •
CVE-2021-21128 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21128
25 Jan 2021 — Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un desbordamiento del búfer de pila en Blink en Google Chrome versiones anteriores a 88.0.4324.96, permitía a un atacante remoto explotar potencialmente la corrupción de la pila por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of cod... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html • CWE-787: Out-of-bounds Write •
CVE-2021-21129 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21129
25 Jan 2021 — Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. Una aplicación de políticas insuficientes en File System API en Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto omitir las restricciones del sistema de archivos por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result i... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html •
CVE-2021-21130 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21130
25 Jan 2021 — Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. Una aplicación de políticas insuficientes en File System API en Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto omitir las restricciones del sistema de archivos por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result i... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html •
CVE-2021-21131 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21131
25 Jan 2021 — Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. Una aplicación de políticas insuficientes en File System API en Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto omitir las restricciones del sistema de archivos por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result i... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2021-21132 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21132
25 Jan 2021 — Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. Una implementación inapropiada en DevTools en Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto llevar a cabo potencialmente un escape del sandbox por medio de una Extension de Chrome diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
CVE-2021-21133 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21133
25 Jan 2021 — Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page. Una aplicación de políticas insuficientes en Downloads en Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante que convenció a un usuario de descargar archivos para omitir las restricciones de navegación por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chr... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html •
CVE-2021-21134 – Debian Security Advisory 4846-1
https://notcve.org/view.php?id=CVE-2021-21134
25 Jan 2021 — Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page. La Interfaz de Usuario de seguridad incorrecta en Page Info en Google Chrome en iOS versiones anteriores a 88.0.4324.96, permitió a un atacante remoto falsificar la Interfaz de Usuario de seguridad por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary ex... • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html • CWE-290: Authentication Bypass by Spoofing •