Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4671

Опубликовано: 10 мая 2024
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

A use after free vulnerability was found in the Chromium web browser.

Отчет

Chromium is not shipped in any supported Red Hat offerings.

Меры по смягчению последствий

Until updated packages are released for Fedora and EPEL, consider temporarily swapping to an alternative web browser such as Firefox or severely restricting activity to sites you know well and trust.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6chromium-browserOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2280246chromium-browser: use after free in Visuals

EPSS

Процентиль: 20%
0.00064
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 1 года назад

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
около 1 года назад

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

msrc
около 1 года назад

Chromium: CVE-2024-4671 Use after free in Visuals

CVSS3: 9.6
debian
около 1 года назад

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 all ...

CVSS3: 9.6
github
около 1 года назад

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 20%
0.00064
Низкий

9.6 Critical

CVSS3