CVE-2024-8198
https://notcve.org/view.php?id=CVE-2024-8198
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html https://issues.chromium.org/issues/360758697 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-122: Heap-based Buffer Overflow •
CVE-2024-8194
https://notcve.org/view.php?id=CVE-2024-8194
Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html https://issues.chromium.org/issues/360533914 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2024-8193
https://notcve.org/view.php?id=CVE-2024-8193
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html https://issues.chromium.org/issues/360265320 • CWE-122: Heap-based Buffer Overflow •
CVE-2024-40671 – PowerVR DevmemIntChangeSparse2() Use-After-Free
https://notcve.org/view.php?id=CVE-2024-40671
In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. PowerVR suffers from a use-after-free vulnerability in DevmemIntChangeSparse2() on a PMRGetUID() call. • https://source.android.com/security/bulletin/2024-11-01 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2024-8035
https://notcve.org/view.php?id=CVE-2024-8035
Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) • https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html https://issues.chromium.org/issues/40059470 •