Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4947

Опубликовано: 15 мая 2024
Источник: redhat
CVSS3: 8.8

Описание

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A type confusion vulnerability was found in the Chromium web browser. This flaw allows an unauthenticated, remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Отчет

Chromium is not shipped in any Red Hat offerings.

Меры по смягчению последствий

Until updated packages are released for Fedora and EPEL, consider temporarily swapping to an alternative web browser such as Firefox or severely restricting activity to sites you know well and trust.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6chromium-browserOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2281874chromium-browser: Type Confusion in V8

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 1 года назад

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
около 1 года назад

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
около 1 года назад

Chromium: CVE-2024-4947 Type Confusion in V8

CVSS3: 9.6
debian
около 1 года назад

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a ...

CVSS3: 8.8
github
около 1 года назад

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3