CVE-2024-7005
https://notcve.org/view.php?id=CVE-2024-7005
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/40068800 • CWE-20: Improper Input Validation CWE-807: Reliance on Untrusted Inputs in a Security Decision •
CVE-2024-7004
https://notcve.org/view.php?id=CVE-2024-7004
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/40063014 • CWE-20: Improper Input Validation CWE-863: Incorrect Authorization •
CVE-2024-7003
https://notcve.org/view.php?id=CVE-2024-7003
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/338233148 • CWE-358: Improperly Implemented Security Check for Standard •
CVE-2024-6994
https://notcve.org/view.php?id=CVE-2024-6994
Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/339686368 • CWE-122: Heap-based Buffer Overflow •
CVE-2024-6997
https://notcve.org/view.php?id=CVE-2024-6997
Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/325293263 • CWE-416: Use After Free •