CVE-2023-2940 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2940
30 May 2023 — Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html •
CVE-2023-2939 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2939
30 May 2023 — Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2023-2938 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2938
30 May 2023 — Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html •
CVE-2023-2937 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2937
30 May 2023 — Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html •
CVE-2023-2936 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2936
30 May 2023 — Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://packetstorm.news/files/id/173197 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2023-2935 – Chrome v8::internal::Object::SetPropertyWithAccessor Type Confusion
https://notcve.org/view.php?id=CVE-2023-2935
30 May 2023 — Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://packetstorm.news/files/id/173196 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2023-2934 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2934
30 May 2023 — Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) During a Mojo IPC method call, there are multiple stages of validation and deserialization that take place. These assume that the contents of the message cannot be modified during the deserialization process, but the new core_ipcz implementation returns message contents directly in shared memory. • https://packetstorm.news/files/id/173259 • CWE-787: Out-of-bounds Write •
CVE-2023-2933 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2933
30 May 2023 — Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html • CWE-416: Use After Free •
CVE-2023-2932 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2932
30 May 2023 — Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html • CWE-416: Use After Free •
CVE-2023-2931 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-2931
30 May 2023 — Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.html • CWE-416: Use After Free •