Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47256
HistoryMay 30, 2024 - 1:50 a.m.

Heap Buffer Overflow

2024-05-3001:50:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
chromium
vulnerability
heap buffer overflow
bounds checking
html page
remote attacker
out-of-bounds memory read
software

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0

Percentile

15.5%

chromium is vulnerable to a Heap Buffer Overflow. This vulnerability due to inadequate bounds checking via a crafted HTML page, allows a remote attacker to perform an out-of-bounds memory read.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0

Percentile

15.5%