VDB
CVE-2023-0930
CVE-2023-0930
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund mehrerer Use-after-free-Fehler, eines Heap-Pufferüberlaufs und eines Integer-Überlaufs in den Komponenten Promts, Web Payments API, SwiftShader, Vulkan, Video, WebRTC und PDF. Ein entfernter, anonymer Angreifer kann diese Schwachstellen, um unbekannte Auswirkungen zu verursachen. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.55% · 68.2th percentile
Risk Scores
EPSS Score
0.55%
68.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IGEL | IGEL OS < 11.08.290 | |
| Fedora | Fedora Linux | |
| Gentoo | Gentoo Linux | |
| Ubuntu | Ubuntu Linux | |
| Debian | Debian Linux |
Timeline
- Feb 22, 2023 CVE Published
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 13, 2023 EPSS Score
- Jun 21, 2023 EPSS Score
- Jul 30, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 17, 2023 EPSS Score
- Nov 25, 2023 EPSS Score
- Jan 3, 2024 EPSS Score
- Feb 12, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0465.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0465 advisory
- https://security.gentoo.org/glsa/202309-17 advisory
- https://kb.igel.com/securitysafety/en/isn-2023-03-chromium-vulnerabilities-81501313.html advisory
- https://ubuntu.com/security/notices/USN-5949-1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-a283f53190 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-1dc713f355 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-7b23e5a4b3 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-1cf9c4477b advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://chromereleases.googleblog.com/2023/02/stable-channel-desktop-update_22.html advisory
- https://lists.debian.org/debian-security-announce/2023/msg00048.html advisory