Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46577
HistoryApr 23, 2024 - 5:34 a.m.

Use-After-Free

2024-04-2305:34:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
chrome
vulnerability
use-after-free
downloads
remote attacker
heap corruption
html page}.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

40.7%

chrome is vulnerable to a Use-after-Free. The vulnerability is due to a use-after-free issue in the Downloads component of Google Chrome, allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

40.7%