VDB
CVE-2024-4060
CVE-2024-4060
PUBLISHED
In Google Chrome und Microsoft Edge bestehen mehrere Schwachstellen. Diese Fehler bestehen in den Komponenten ANGLE, V8 und DAWN aufgrund einer Typverwechslung, eines Use-after-free und eines Out-of-bounds-Problems. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um nicht spezifizierte Auswirkungen zu verursachen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.22% · 44.5th percentile
Risk Scores
EPSS Score
0.22%
44.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gentoo | Gentoo Linux | |
| Fedora | Fedora Linux | |
| Google Chrome LTS <120.0.6099.309 | ||
| IGEL | IGEL OS 11 | |
| SUSE | SUSE openSUSE | |
| Microsoft | Microsoft Edge <124.0.2478.67 | |
| IGEL | IGEL OS 12 | |
| Google Chrome <124.0.6367.78 | ||
| Google Chrome <124.0.6367.79 | ||
| Debian | Debian Linux |
Exploit Intelligence
- https://issues.chromium.org/issues/333420620 (nist-nvd)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IDLUD644WEWGOFKMZWC2K7Z4CQOKQYR7/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4PCXKCOVBUUU6GOSN46DCPI4HMER3PJ/ (circl)
- https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_24.html (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOC3HLIZCGMIJLJ6LME5UWUUIFLXEGRN/ (circl)
Timeline
- Apr 24, 2024 CVE Published
- May 2, 2024 EPSS Score
- May 26, 2024 EPSS Score
- Jul 15, 2024 EPSS Score
- Aug 8, 2024 EPSS Score
- Sep 2, 2024 EPSS Score
- Sep 26, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Nov 14, 2024 EPSS Score
- Dec 9, 2024 EPSS Score
- Jan 2, 2025 EPSS Score
- Jan 27, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0962.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0962 advisory
- http://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_24.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-de34d9d61f advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-0c24da3136 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-decb7e94a1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-2c9be9d949 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#april-26-2024 advisory
- https://lists.debian.org/debian-security-announce/2024/msg00084.html advisory
- http://chromereleases.googleblog.com/2024/04/long-term-support-channel-update-for_29.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-0539d2c8b0 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-68b6d0dafe advisory
- https://kb.igel.com/securitysafety/en/isn-2024-11-chromium-critical-vulnerability-122902558.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-5cf9499b62 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-808f3961ef advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-f74fbce604 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/2S7S4HVABEMIRHPQD4H3O6EA36PLCUCI/ advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-6f1c3198f5 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2S7S4HVABEMIRHPQD4H3O6EA36PLCUCI/ advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-38d250bafc advisory
…and 6 more