VDB
CVE-2023-0927
CVE-2023-0927
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund mehrerer Use-after-free-Fehler, eines Heap-Pufferüberlaufs und eines Integer-Überlaufs in den Komponenten Promts, Web Payments API, SwiftShader, Vulkan, Video, WebRTC und PDF. Ein entfernter, anonymer Angreifer kann diese Schwachstellen, um unbekannte Auswirkungen zu verursachen. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.33% · 56.4th percentile
Risk Scores
EPSS Score
0.33%
56.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | |
| Ubuntu | Ubuntu Linux | |
| IGEL | IGEL OS < 11.08.290 | |
| Gentoo | Gentoo Linux | |
| Fedora | Fedora Linux |
Timeline
- Feb 22, 2023 CVE Published
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 13, 2023 EPSS Score
- Jun 21, 2023 EPSS Score
- Jul 31, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 17, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Jan 4, 2024 EPSS Score
- Feb 12, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0465.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0465 advisory
- https://security.gentoo.org/glsa/202309-17 advisory
- https://kb.igel.com/securitysafety/en/isn-2023-03-chromium-vulnerabilities-81501313.html advisory
- https://ubuntu.com/security/notices/USN-5949-1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-a283f53190 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-1dc713f355 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-7b23e5a4b3 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-1cf9c4477b advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://chromereleases.googleblog.com/2023/02/stable-channel-desktop-update_22.html advisory
- https://lists.debian.org/debian-security-announce/2023/msg00048.html advisory