Search CVE reports


Toggle filters

2301 – 2310 of 5640 results


CVE-2023-5346

Medium priority
Not affected

Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not in release Ignored
Show less packages

CVE-2023-44488

Medium priority

Some fixes available 12 of 24

VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

10 affected packages

chromium-browser, firefox, libvpx, mozjs102, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not affected Not in release Ignored
firefox Not affected Not affected Not affected Fixed Ignored
libvpx Fixed Fixed Fixed Fixed Fixed
mozjs102 Not in release Ignored Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored Not in release
mozjs78 Not in release Not in release Ignored Not in release Not in release
mozjs91 Not in release Not in release Ignored Not in release Not in release
thunderbird Not affected Not affected Not affected Not in release Ignored
Show all 10 packages Show less packages

CVE-2023-5217

High priority

Some fixes available 13 of 23

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

10 affected packages

chromium-browser, firefox, libvpx, mozjs102, mozjs38...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not in release Ignored
firefox Not affected Not affected Fixed Ignored
libvpx Not affected Fixed Fixed Fixed
mozjs102 Ignored Ignored Not in release Not in release
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Ignored Not in release
mozjs78 Not in release Ignored Not in release Not in release
mozjs91 Not in release Ignored Not in release Not in release
thunderbird Fixed Fixed Fixed Ignored
Show all 10 packages Show less packages

CVE-2023-5187

Medium priority
Not affected

Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security...

1 affected package

chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not in release Ignored
Show less packages

CVE-2023-5186

Medium priority
Not affected

Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium...

1 affected package

chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not in release Ignored
Show less packages

CVE-2023-43646

Medium priority
Needs evaluation

get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead...

3 affected packages

node-get-func-name, qt6-webengine, chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-get-func-name Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
qt6-webengine Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
chromium-browser Not affected Not affected Not affected Not in release Ignored
Show less packages

CVE-2010-1765

Medium priority
Ignored

Rejected reason: This candidate is unused by its CNA.

2 affected packages

chromium-browser, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
webkit
Show less packages

CVE-2023-4909

Medium priority
Not affected

Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not in release Ignored
Show less packages

CVE-2023-4908

Medium priority
Not affected

Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not in release Ignored
Show less packages

CVE-2023-4907

Medium priority
Not affected

Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not in release Ignored
Show less packages