Show filters
1,221 Total Results
Displaying 111-120 of 1,221
Sort by:
Attacker Value
Unknown

CVE-2023-5481

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-5479

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-5478

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Attacker Value
Unknown

CVE-2023-5477

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)
Attacker Value
Unknown

CVE-2023-5476

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-5475

Disclosure Date: October 11, 2023 (last updated November 16, 2023)
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-5474

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-5473

Disclosure Date: October 11, 2023 (last updated October 21, 2023)
Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Attacker Value
Unknown

CVE-2023-5218

Disclosure Date: October 11, 2023 (last updated November 16, 2023)
Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Attacker Value
Unknown

CVE-2023-44981

Disclosure Date: October 11, 2023 (last updated February 14, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.