
CVE-2024-3840 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3840
17 Apr 2024 — Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) La aplicación insuficiente de políticas en Site Isolation en Google Chrome antes de 124.0.6367.60 permitió a un atacante remoto eludir las restricciones de navegación a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Security issues were discovered in Chromium, whic... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-285: Improper Authorization •

CVE-2024-3839 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3839
17 Apr 2024 — Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) La lectura fuera de los límites en fuentes en Google Chrome anterior a 124.0.6367.60 permitía a un atacante remoto obtener información potencialmente confidencial de la memoria del proceso a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Security issues wer... • https://github.com/vin01/poc-cve-2024-38396 • CWE-125: Out-of-bounds Read •

CVE-2024-3838 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3838
17 Apr 2024 — Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium) La implementación inadecuada de Autocompletar en Google Chrome anterior a 124.0.6367.60 permitió que un atacante convenciera a un usuario de instalar una aplicación maliciosa para realizar una suplantación de la interfaz de usuario a través de una aplicación manipulada. (Severidad de... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-358: Improperly Implemented Security Check for Standard •

CVE-2024-3837 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3837
17 Apr 2024 — Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Use after free en QUIC en Google Chrome anterior a 124.0.6367.60 permitía a un atacante remoto que había comprometido el proceso de renderizado explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) Secu... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-416: Use After Free •

CVE-2024-3834 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3834
17 Apr 2024 — Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Descargas en Google Chrome anterior a 124.0.6367.60 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) Security issues were discovered in Chromium, which could result in the execution of arbit... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-416: Use After Free •

CVE-2024-3833 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3833
17 Apr 2024 — Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) La corrupción de objetos en WebAssembly en Google Chrome anterior a 124.0.6367.60 permitía a un atacante remoto explotar potencialmente la corrupción de objetos a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) Security issues were discovered in Chromium, which could result in the... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-374: Passing Mutable Objects to an Untrusted Method •

CVE-2024-3832 – Debian Security Advisory 5668-1
https://notcve.org/view.php?id=CVE-2024-3832
17 Apr 2024 — Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) La corrupción de objetos en V8 en Google Chrome anterior a 124.0.6367.60 permitía a un atacante remoto explotar potencialmente la corrupción de objetos a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) Security issues were discovered in Chromium, which could result in the execution of arbi... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2024-3914 – Microsoft Edge DOMArrayBuffer Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-3914
15 Apr 2024 — Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en V8 en Google Chrome anterior a 124.0.6367.60 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html • CWE-416: Use After Free •

CVE-2024-3515 – Debian Security Advisory 5656-1
https://notcve.org/view.php?id=CVE-2024-3515
10 Apr 2024 — Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Dawn en Google Chrome anterior a 123.0.6312.122 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) Security issues were discovered in Chromium, which could result in the execution of arbitrary cod... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_10.html • CWE-416: Use After Free •

CVE-2024-3516 – Debian Security Advisory 5656-1
https://notcve.org/view.php?id=CVE-2024-3516
10 Apr 2024 — Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) El desbordamiento de búfer de almacenamiento dinámico en ANGLE en Google Chrome anterior a 123.0.6312.122 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) Security issues were discovered in Chromium, which... • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_10.html • CWE-122: Heap-based Buffer Overflow •