
CVE-2024-1939 – Debian Security Advisory 5634-1
https://notcve.org/view.php?id=CVE-2024-1939
29 Feb 2024 — Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Type Confusion en V8 en Google Chrome anterior a 122.0.6261.94 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary ... • https://github.com/rycbar77/CVE-2024-1939 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2023-52160 – wpa_supplicant: potential authorization bypass
https://notcve.org/view.php?id=CVE-2023-52160
22 Feb 2024 — The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks. La implementación de PEAP en wpa_supplicant hasta ... • https://github.com/Helica-core/eap_pwn • CWE-285: Improper Authorization CWE-287: Improper Authentication •

CVE-2024-1676 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1676
21 Feb 2024 — Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low) La implementación inadecuada en la navegación en Google Chrome anterior a 122.0.6261.57 permitió a un atacante remoto falsificar la interfaz de usuario de seguridad a través de una página HTML manipulada. (Severidad de seguridad de Chrome: baja) An update that fixes 12 vulnerabilities is now available. This update for chr... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-1675 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1675
21 Feb 2024 — Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) La aplicación insuficiente de políticas en Descargas en Google Chrome anteriores a 122.0.6261.57 permitió a un atacante remoto eludir las restricciones del sistema de archivos a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) An update that fixes 12 vulnerabilities is now... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-284: Improper Access Control •

CVE-2024-1674 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1674
21 Feb 2024 — Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada en Navegación en Google Chrome anterior a 122.0.6261.57 permitió a un atacante remoto eludir las restricciones de navegación a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) An update that fixes 12 vulnerabilities is now available. This update... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html •

CVE-2024-1673 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1673
21 Feb 2024 — Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium) Use after free en Accesibilidad en Google Chrome anterior a 122.0.6261.57 permitía a un atacante remoto que había comprometido el proceso de renderizado explotar potencialmente la corrupción del montón a través de gestos de interfaz de usuario específicos. (Severidad de ... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-416: Use After Free •

CVE-2024-1672 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1672
21 Feb 2024 — Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada de la Política de seguridad de contenido en Google Chrome anterior a 122.0.6261.57 permitió a un atacante remoto eludir la política de seguridad de contenido a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) An update that fixes 12... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-474: Use of Function with Inconsistent Implementations •

CVE-2024-1671 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1671
21 Feb 2024 — Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada de Site Isolation en Google Chrome anterior a 122.0.6261.57 permitió a un atacante remoto eludir la política de seguridad de contenido a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media) An update that fixes 12 vulnerabilities is now availabl... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-693: Protection Mechanism Failure •

CVE-2024-1670 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1670
21 Feb 2024 — Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Use after free en Mojo en Google Chrome anterior a 122.0.6261.57 permitía a un atacante remoto explotar potencialmente la corrupción del montón a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) An update that fixes 12 vulnerabilities is now available. This update for chromium fixes the follow... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-416: Use After Free •

CVE-2024-1669 – Debian Security Advisory 5629-1
https://notcve.org/view.php?id=CVE-2024-1669
21 Feb 2024 — Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) El acceso a la memoria fuera de los límites en Blink en Google Chrome anterior a 122.0.6261.57 permitía a un atacante remoto realizar un acceso a la memoria fuera de los límites a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) An update that fixes 12 vulnerabilities is now avai... • https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop_20.html • CWE-125: Out-of-bounds Read •