Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46394
HistoryApr 14, 2024 - 3:25 a.m.

Use-After-Free

2024-04-1403:25:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
use-after-free
heap corruption
remote attacker
html page
software vulnerability

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

15.5%

chromium is vulnerable to Use-after-free. The vulnerability is due to improper handling of memory within the web GPU API implementation, the web GPU API implementation, allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

15.5%