Page 26 of 151 results (0.043 seconds)

CVSS: 6.3EPSS: 1%CPEs: 1EXPL: 0

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Una Vulnerabilidad de Divulgación de Información en Microsoft Edge (basado en Chromium). • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36929 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Microsoft Edge (basado en Chromium). Este ID de CVE es diferente de CVE-2021-36931. This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Edge. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within Edge Installer. By creating a directory junction, an attacker can abuse Edge Installer to delete a file. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36928 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Una vulnerabilidad de Escalada de Privilegios en Microsoft Edge (basado en Chromium) • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33741 •

CVSS: 8.8EPSS: 0%CPEs: 6EXPL: 1

Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de la memoria previamente liberada en Web Sockets en Google Chrome en Linux versiones anteriores a 88.0.4324.182, permitía a un atacante remoto explotar potencialmente una corrupción de la pila por medio de una página HTML diseñada • https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_16.html https://crbug.com/1170657 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BI6ZIJQYP5DFMYVX4J5OGOU2NQLEZ3SB https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FE5SIKEVYTMDCC5OSXGOM2KRPYLHYMQX https://security.gentoo.org/glsa/202104-08 • CWE-416: Use After Free •

CVSS: 9.6EPSS: 0%CPEs: 2EXPL: 0

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. Una implementación inapropiada en DevTools en Google Chrome versiones anteriores a 88.0.4324.96, permitió a un atacante remoto llevar a cabo potencialmente un escape del sandbox por medio de una Extension de Chrome diseñada • https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html https://crbug.com/1128206 https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-21132 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •