VDB
CVE-2023-0933
CVE-2023-0933
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund mehrerer Use-after-free-Fehler, eines Heap-Pufferüberlaufs und eines Integer-Überlaufs in den Komponenten Promts, Web Payments API, SwiftShader, Vulkan, Video, WebRTC und PDF. Ein entfernter, anonymer Angreifer kann diese Schwachstellen, um unbekannte Auswirkungen zu verursachen. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.38% · 59.8th percentile
Risk Scores
EPSS Score
0.38%
59.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | |
| IGEL | IGEL OS < 11.08.290 | |
| Fedora | Fedora Linux | |
| Debian | Debian Linux | |
| Gentoo | Gentoo Linux |
Timeline
- Feb 22, 2023 CVE Published
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 13, 2023 EPSS Score
- Jun 21, 2023 EPSS Score
- Jul 31, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 17, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Jan 4, 2024 EPSS Score
- Feb 12, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0465.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0465 advisory
- https://security.gentoo.org/glsa/202309-17 advisory
- https://kb.igel.com/securitysafety/en/isn-2023-03-chromium-vulnerabilities-81501313.html advisory
- https://ubuntu.com/security/notices/USN-5949-1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-a283f53190 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-1dc713f355 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-7b23e5a4b3 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-1cf9c4477b advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://chromereleases.googleblog.com/2023/02/stable-channel-desktop-update_22.html advisory
- https://lists.debian.org/debian-security-announce/2023/msg00048.html advisory