VDB
CVE-2024-7969
CVE-2024-7969
PUBLISHED
Es bestehen mehrere Schwachstellen in Google Chrome. Diese betreffen die Komponenten V8 und SKIA aufgrund von Heap- Buffer Overflows und Typkonfusion. Sie ermöglichen eine Heap Corruption über eine bösartige HTML-Seite. Ein entfernter, anonymer Angreifer kann diese Schwachstellen zur Ausführung von beliebigem Code ausnutzen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.17% · 38.5th percentile
Risk Scores
EPSS Score
0.17%
38.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Google Chrome Linux <1128.0.6613.113 | ||
| Microsoft | Microsoft Edge Android | |
| Google Chrome Windows <128.0.6613.113/.114 | ||
| Google Chrome Mac <128.0.6613.113/.114 | ||
| SUSE | SUSE openSUSE | |
| Microsoft | Microsoft Edge <128.0.2739.42 | |
| Google Chrome <128.0.6613.84 | ||
| Google Chrome <128.0.6613.85 | ||
| Debian | Debian Linux |
Timeline
- Aug 21, 2024 CVE Published
- Aug 22, 2024 EPSS Score
- Sep 6, 2024 CVE Updated
- Sep 12, 2024 EPSS Score
- Oct 2, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 23, 2024 EPSS Score
- Nov 12, 2024 EPSS Score
- Dec 4, 2024 EPSS Score
- Dec 24, 2024 EPSS Score
- Jan 14, 2025 EPSS Score
- Feb 3, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1901.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1901 advisory
- https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/QKC6ROFWBIXXM5S5SYRWQ74OU24BX5KT/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/G5G3DFUIZH3E3T5UIPSI3LSGCI5KE3NF/ advisory
- https://lists.debian.org/debian-security-announce/2024/msg00170.html advisory
- https://lists.debian.org/debian-security-announce/2024/msg00174.html advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/RIZKO6CBLHDIQSHSR5OD4LHRUHJOZWTG/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RIZKO6CBLHDIQSHSR5OD4LHRUHJOZWTG/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/TJMLQH7THP267EBNFZ3ECENLIIFCBW5H/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GYIF7RESU4PKGREHH5YVHUYYGB57P4CQ/ advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1917.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1917 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#august-22-2024 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1946.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1946 advisory
- https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html advisory