‼ CVE-2021-30589 ‼
📖 Read
via "National Vulnerability Database".
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30569 ‼
📖 Read
via "National Vulnerability Database".
Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30581 ‼
📖 Read
via "National Vulnerability Database".
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30576 ‼
📖 Read
via "National Vulnerability Database".
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30582 ‼
📖 Read
via "National Vulnerability Database".
Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30573 ‼
📖 Read
via "National Vulnerability Database".
Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30588 ‼
📖 Read
via "National Vulnerability Database".
Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30586 ‼
📖 Read
via "National Vulnerability Database".
Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30584 ‼
📖 Read
via "National Vulnerability Database".
Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30567 ‼
📖 Read
via "National Vulnerability Database".
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to open DevTools to potentially exploit heap corruption via specific user gesture.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33332 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portlet_configuration_css_web_portlet_PortletConfigurationCSSPortlet_portletResource parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30578 ‼
📖 Read
via "National Vulnerability Database".
Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30580 ‼
📖 Read
via "National Vulnerability Database".
Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30572 ‼
📖 Read
via "National Vulnerability Database".
Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30565 ‼
📖 Read
via "National Vulnerability Database".
Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30575 ‼
📖 Read
via "National Vulnerability Database".
Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33334 ‼
📖 Read
via "National Vulnerability Database".
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30583 ‼
📖 Read
via "National Vulnerability Database".
Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-30568 ‼
📖 Read
via "National Vulnerability Database".
Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
🦿 True cybersecurity means centering policies on employee behavior, report says 🦿
📖 Read
via "Tech Republic".
Protecting systems from bad actors is essential, but all the firewalls in the world are useless against the modern hacker who targets human weaknesses instead of digital ones.📖 Read
via "Tech Republic".
TechRepublic
True cybersecurity means centering policies on employee behavior, report says
Protecting systems from bad actors is essential, but all the firewalls in the world are useless against the modern hacker who targets human weaknesses instead of digital ones.
‼ CVE-2021-37232 ‼
📖 Read
via "National Vulnerability Database".
A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of buffer size of uint32_buffer while reading more bytes in APar_read64.📖 Read
via "National Vulnerability Database".