CVE-2024-8906
https://notcve.org/view.php?id=CVE-2024-8906
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html https://issues.chromium.org/issues/352681108 •
CVE-2024-8905
https://notcve.org/view.php?id=CVE-2024-8905
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html https://issues.chromium.org/issues/359949835 • CWE-122: Heap-based Buffer Overflow •
CVE-2024-8904
https://notcve.org/view.php?id=CVE-2024-8904
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html https://issues.chromium.org/issues/365376497 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2024-22013
https://notcve.org/view.php?id=CVE-2024-22013
U-Boot environment is read from unauthenticated partition. • https://support.google.com/product-documentation/answer/14950962?hl=en&ref_topic=12974021&sjid=9595902703262170957-NA#zippy=%2Cwifi •
CVE-2024-44096
https://notcve.org/view.php?id=CVE-2024-44096
there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. • https://source.android.com/security/bulletin/pixel/2024-09-01 • CWE-453: Insecure Default Variable Initialization •