Unknown · CVSS Not scored
Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Jun 15, 2021 · Updated Aug 3, 2024
Critical · CVSS 9
Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 15, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruption via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 15, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
High · CVSS 7.1
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
High · CVSS 7.5
Reachable assertion due to improper validation of coreset in PDCCH configuration in SA mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Critical · CVSS 9.1
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
Published Jun 16, 2021 · Updated Aug 3, 2024
Critical · CVSS 9.1
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 3, 2024
High · CVSS 8.2
Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 3, 2024
Medium · CVSS 6.5
RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jun 4, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
Published Jun 2, 2021 · Updated Aug 3, 2024
Medium · CVSS 6.5
RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 3, 2024
High · CVSS 7.5
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music
Published Jun 14, 2022 · Updated Aug 3, 2024
Critical · CVSS 9.1
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 3, 2024
High · CVSS 7.5
Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 8.4
Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 3, 2024
High · CVSS 8.4
Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 3, 2024
Critical · CVSS 9.8
Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 3, 2024
High · CVSS 8.4
Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.
Published Jun 9, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
Published Jun 9, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Published Jun 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.
Published Jun 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Published Jun 24, 2021 · Updated Aug 3, 2024