Page 3 of 47 results (0.005 seconds)

CVSS: 9.6EPSS: 44%CPEs: 16EXPL: 12

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) El desbordamiento del búfer de memoria en libwebp en Google Chrome anterior a 116.0.5845.187 y libwebp 1.3.2 permitía a un atacante remoto realizar una escritura en memoria fuera de los límites a través de una página HTML manipulada. (Severidad de seguridad de Chromium: crítica) A heap-based buffer flaw was found in the way libwebp, a library used to process "WebP" image format data, processes certain specially formatted WebP images. An attacker could use this flaw to crash or execute remotely arbitrary code in an application such as a web browser compiled with this library. Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. • https://github.com/alsaeroth/CVE-2023-4863-POC https://github.com/mistymntncop/CVE-2023-4863 https://github.com/LiveOverflow/webp-CVE-2023-4863 https://github.com/bbaranoff/CVE-2023-4863 https://github.com/talbeerysec/BAD-WEBP-CVE-2023-4863 https://github.com/huiwen-yayaya/CVE-2023-4863 https://github.com/CrackerCat/CVE-2023-4863- https://github.com/sarsaeroth/CVE-2023-4863-POC http://www.openwall.com/lists/oss-security/2023/09/21/4 http://www.openwall.com/list • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Microsoft Edge for iOS Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36883 •

CVSS: 3.7EPSS: 0%CPEs: 1EXPL: 0

Microsoft Edge (Chromium-based) Tampering Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28301 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28284 •

CVSS: 8.3EPSS: 0%CPEs: 2EXPL: 0

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios en Microsoft Edge (basado en Chromium). • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-44708 https://security.gentoo.org/glsa/202305-10 https://security.gentoo.org/glsa/202311-11 •