CVE-2022-4437
https://notcve.org/view.php?id=CVE-2022-4437
14 Dec 2022 — Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Mojo IPC en Google Chrome anterior a 108.0.5359.124 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) • https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html • CWE-416: Use After Free •
CVE-2022-4438
https://notcve.org/view.php?id=CVE-2022-4438
14 Dec 2022 — Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Blink Frames en Google Chrome anterior a 108.0.5359.124 permitía a un atacante remoto convencer al usuario de participar en interacciones específicas de la interfaz de usuario para explotar potencialmente la corrupción del montón a trav... • https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html • CWE-416: Use After Free •
CVE-2022-4439
https://notcve.org/view.php?id=CVE-2022-4439
14 Dec 2022 — Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High) Use after free en Aura en Google Chrome en Windows anterior a 108.0.5359.124 permitía a un atacante remoto convencer al usuario de participar en interacciones específicas de la interfaz de usuario para explotar potencialmente la corrupción del mo... • https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html • CWE-416: Use After Free •
CVE-2022-4440
https://notcve.org/view.php?id=CVE-2022-4440
14 Dec 2022 — Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Use after free en Profiles de Google Chrome anteriores a 108.0.5359.124 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) • https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html • CWE-416: Use After Free •
CVE-2022-4262 – Google Chromium V8 Type Confusion Vulnerability
https://notcve.org/view.php?id=CVE-2022-4262
02 Dec 2022 — Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) La confusión de tipos en V8 en Google Chrome anterior a 108.0.5359.94 permitía a un atacante remoto explotar potencialmente la corrupción del heap a través de una página HTML manipulada. (Severidad de seguridad de Chrome: Alta) Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to... • https://github.com/bjrjk/CVE-2022-4262 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2022-4174
https://notcve.org/view.php?id=CVE-2022-4174
29 Nov 2022 — Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) La confusión de tipos en V8 en Google Chrome anterior a 108.0.5359.71 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) • https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2022-4175
https://notcve.org/view.php?id=CVE-2022-4175
29 Nov 2022 — Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Camera Capture en Google Chrome anterior a 108.0.5359.71 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) • https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html • CWE-416: Use After Free •
CVE-2022-4176
https://notcve.org/view.php?id=CVE-2022-4176
29 Nov 2022 — Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: High) La escritura fuera de límites en Lacros Graphics en Google Chrome en Chrome OS y Lacros anterior a 108.0.5359.71 permitía a un atacante remoto que convenciera a un usuario para participar en interacciones de UI específicas para e... • https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html • CWE-787: Out-of-bounds Write •
CVE-2022-4177
https://notcve.org/view.php?id=CVE-2022-4177
29 Nov 2022 — Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High) El Use after free en Extensiones de Google Chrome anteriores a 108.0.5359.71 permitió que un atacante convenciera a un usuario de instalar una extensión para explotar potencialmente la corrupción del montón a través de una extensión de Chrome manipulada... • https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html • CWE-416: Use After Free •
CVE-2022-4178 – Chrome Synchronous Mojo Use-After-Free
https://notcve.org/view.php?id=CVE-2022-4178
29 Nov 2022 — Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Mojo en Google Chrome anterior a 108.0.5359.71 permitía a un atacante remoto que había comprometido el proceso de renderizado explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) A design ... • https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html • CWE-416: Use After Free •