1. Remote Code Execution - Microsoft Exchange Server (CVE-2021-26412) - Critical [700] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object) |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.9 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 9.1. Based on Microsoft data |
2. Remote Code Execution - Microsoft Exchange Server (CVE-2021-26855) - Critical [700] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object, AttackerKB object), AttackerKB, Microsoft |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.9 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 9.1. Based on Microsoft data |
3. Remote Code Execution - Microsoft Exchange Server (CVE-2021-27078) - Critical [700] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object) |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.9 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 9.1. Based on Microsoft data |
4. Remote Code Execution - Microsoft Exchange Server (CVE-2021-26857) - Critical [672] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object, AttackerKB object), AttackerKB, Microsoft |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.7 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 7.8. Based on Microsoft data |
5. Remote Code Execution - Microsoft Exchange Server (CVE-2021-26858) - Critical [672] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-27065, CVE-2021-27078.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object, AttackerKB object), AttackerKB, Microsoft |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.7 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 7.8. Based on Microsoft data |
6. Remote Code Execution - Microsoft Exchange Server (CVE-2021-27065) - Critical [672] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27078.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object, AttackerKB object), AttackerKB, Microsoft |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.7 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 7.8. Based on Microsoft data |
7. Remote Code Execution - Microsoft Exchange Server (CVE-2021-26854) - Critical [659] Description: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object, AttackerKB object, AttackerKB object) |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 1.0 | 15 | Remote Code Execution |
Vulnerable Product is Common | 0.7 | 14 | Microsoft Exchange Server |
CVSS Base Score | 0.6 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 6.6. Based on Microsoft data |
8. Memory Corruption - Google Chrome (CVE-2020-16044) - High [516] Description: Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at AttackerKB |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
9. Memory Corruption - Google Chrome (CVE-2021-21148) - High [516] Description: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object), AttackerKB |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
10. Memory Corruption - Google Chrome (CVE-2021-21166) - High [516] Description: Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object), AttackerKB |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
11. Memory Corruption - Google Chrome (CVE-2021-21193) - High [516] Description: Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 1.0 | 18 | Exploitation in the wild is mentioned at Vulners (AttackerKB object), AttackerKB |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
12. Security Feature Bypass - Microsoft Edge (Chromium-based) (CVE-2021-24113) - High [401] Description: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.9 | 15 | Security Feature Bypass |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.5 | 10 | Vulnerability Severity Rating based on CVSS Base Score is 5.4. Based on Microsoft data |
13. Memory Corruption - Google Chrome (CVE-2021-21118) - Medium [272] Description: Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
14. Memory Corruption - Google Chrome (CVE-2021-21119) - Medium [272] Description: Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
15. Memory Corruption - Google Chrome (CVE-2021-21120) - Medium [272] Description: Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
16. Memory Corruption - Google Chrome (CVE-2021-21122) - Medium [272] Description: Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
17. Memory Corruption - Google Chrome (CVE-2021-21128) - Medium [272] Description: Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
18. Memory Corruption - Google Chrome (CVE-2021-21140) - Medium [272] Description: Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
19. Memory Corruption - Google Chrome (CVE-2021-21143) - Medium [272] Description: Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
20. Memory Corruption - Google Chrome (CVE-2021-21144) - Medium [272] Description: Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
21. Memory Corruption - Google Chrome (CVE-2021-21145) - Medium [272] Description: Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
22. Memory Corruption - Google Chrome (CVE-2021-21149) - Medium [272] Description: Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
23. Memory Corruption - Google Chrome (CVE-2021-21152) - Medium [272] Description: Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
24. Memory Corruption - Google Chrome (CVE-2021-21153) - Medium [272] Description: Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
25. Memory Corruption - Google Chrome (CVE-2021-21156) - Medium [272] Description: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
26. Memory Corruption - Google Chrome (CVE-2021-21157) - Medium [272] Description: Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
27. Memory Corruption - Google Chrome (CVE-2021-21159) - Medium [272] Description: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
28. Memory Corruption - Google Chrome (CVE-2021-21160) - Medium [272] Description: Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
29. Memory Corruption - Google Chrome (CVE-2021-21161) - Medium [272] Description: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
30. Memory Corruption - Google Chrome (CVE-2021-21162) - Medium [272] Description: Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
31. Memory Corruption - Google Chrome (CVE-2021-21165) - Medium [272] Description: Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
32. Memory Corruption - Google Chrome (CVE-2021-21167) - Medium [272] Description: Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
33. Memory Corruption - Google Chrome (CVE-2021-21169) - Medium [272] Description: Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
34. Memory Corruption - Google Chrome (CVE-2021-21179) - Medium [272] Description: Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
35. Memory Corruption - Google Chrome (CVE-2021-21180) - Medium [272] Description: Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
36. Memory Corruption - Google Chrome (CVE-2021-21188) - Medium [272] Description: Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
37. Memory Corruption - Google Chrome (CVE-2021-21191) - Medium [272] Description: Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
38. Memory Corruption - Google Chrome (CVE-2021-21192) - Medium [272] Description: Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.6 | 15 | Memory Corruption |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
39. Spoofing - Google Chrome (CVE-2021-21187) - Medium [232] Description: Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0.4 | 15 | Spoofing |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
40. Unknown Vulnerability Type - Google Chrome (CVE-2021-21121) - Low [151] Description: Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
41. Unknown Vulnerability Type - Google Chrome (CVE-2021-21123) - Low [151] Description: Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
42. Unknown Vulnerability Type - Google Chrome (CVE-2021-21124) - Low [151] Description: Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
43. Unknown Vulnerability Type - Google Chrome (CVE-2021-21125) - Low [151] Description: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
44. Unknown Vulnerability Type - Google Chrome (CVE-2021-21126) - Low [151] Description: Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
45. Unknown Vulnerability Type - Google Chrome (CVE-2021-21127) - Low [151] Description: Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
46. Unknown Vulnerability Type - Google Chrome (CVE-2021-21129) - Low [151] Description: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
47. Unknown Vulnerability Type - Google Chrome (CVE-2021-21130) - Low [151] Description: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
48. Unknown Vulnerability Type - Google Chrome (CVE-2021-21131) - Low [151] Description: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
49. Unknown Vulnerability Type - Google Chrome (CVE-2021-21132) - Low [151] Description: Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
50. Unknown Vulnerability Type - Google Chrome (CVE-2021-21133) - Low [151] Description: Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
51. Unknown Vulnerability Type - Google Chrome (CVE-2021-21134) - Low [151] Description: Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
52. Unknown Vulnerability Type - Google Chrome (CVE-2021-21135) - Low [151] Description: Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
53. Unknown Vulnerability Type - Google Chrome (CVE-2021-21136) - Low [151] Description: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
54. Unknown Vulnerability Type - Google Chrome (CVE-2021-21137) - Low [151] Description: Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
55. Unknown Vulnerability Type - Google Chrome (CVE-2021-21139) - Low [151] Description: Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
56. Unknown Vulnerability Type - Google Chrome (CVE-2021-21141) - Low [151] Description: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
57. Unknown Vulnerability Type - Google Chrome (CVE-2021-21142) - Low [151] Description: Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
58. Unknown Vulnerability Type - Google Chrome (CVE-2021-21146) - Low [151] Description: Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
59. Unknown Vulnerability Type - Google Chrome (CVE-2021-21147) - Low [151] Description: Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
60. Unknown Vulnerability Type - Google Chrome (CVE-2021-21150) - Low [151] Description: Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
61. Unknown Vulnerability Type - Google Chrome (CVE-2021-21151) - Low [151] Description: Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
62. Unknown Vulnerability Type - Google Chrome (CVE-2021-21154) - Low [151] Description: Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
63. Unknown Vulnerability Type - Google Chrome (CVE-2021-21155) - Low [151] Description: Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
64. Unknown Vulnerability Type - Google Chrome (CVE-2021-21163) - Low [151] Description: Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
65. Unknown Vulnerability Type - Google Chrome (CVE-2021-21164) - Low [151] Description: Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
66. Unknown Vulnerability Type - Google Chrome (CVE-2021-21168) - Low [151] Description: Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
67. Unknown Vulnerability Type - Google Chrome (CVE-2021-21170) - Low [151] Description: Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
68. Unknown Vulnerability Type - Google Chrome (CVE-2021-21171) - Low [151] Description: Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
69. Unknown Vulnerability Type - Google Chrome (CVE-2021-21172) - Low [151] Description: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
70. Unknown Vulnerability Type - Google Chrome (CVE-2021-21173) - Low [151] Description: Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
71. Unknown Vulnerability Type - Google Chrome (CVE-2021-21174) - Low [151] Description: Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
72. Unknown Vulnerability Type - Google Chrome (CVE-2021-21175) - Low [151] Description: Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
73. Unknown Vulnerability Type - Google Chrome (CVE-2021-21176) - Low [151] Description: Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
74. Unknown Vulnerability Type - Google Chrome (CVE-2021-21177) - Low [151] Description: Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
75. Unknown Vulnerability Type - Google Chrome (CVE-2021-21178) - Low [151] Description: Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
76. Unknown Vulnerability Type - Google Chrome (CVE-2021-21181) - Low [151] Description: Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
77. Unknown Vulnerability Type - Google Chrome (CVE-2021-21182) - Low [151] Description: Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
78. Unknown Vulnerability Type - Google Chrome (CVE-2021-21183) - Low [151] Description: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
79. Unknown Vulnerability Type - Google Chrome (CVE-2021-21184) - Low [151] Description: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
80. Unknown Vulnerability Type - Google Chrome (CVE-2021-21185) - Low [151] Description: Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
81. Unknown Vulnerability Type - Google Chrome (CVE-2021-21186) - Low [151] Description: Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
82. Unknown Vulnerability Type - Google Chrome (CVE-2021-21189) - Low [151] Description: Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
83. Unknown Vulnerability Type - Google Chrome (CVE-2021-21190) - Low [151] Description: Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0.8 | 14 | Web browser |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
84. Unknown Vulnerability Type - Unknown Product (CVE-2020-17163) - Low [0] Description:
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0 | 14 | Unclassified product |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |
85. Unknown Vulnerability Type - Unknown Product (CVE-2020-27844) - Low [0] Description: A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
component | value | weight | comment |
---|---|---|---|
Exploited in the Wild | 0 | 18 | Exploitation in the wild is NOT found at Vulners, Microsoft and AttackerKB websites |
Public Exploit Exists | 0 | 17 | Public exploit is NOT found at Vulners website |
Criticality of Vulnerability Type | 0 | 15 | Unknown Vulnerability Type |
Vulnerable Product is Common | 0 | 14 | Unclassified product |
CVSS Base Score | 0.0 | 10 | Vulnerability Severity Rating based on CVSS Base Score is NA. No data. |