VDB
CVE-2024-9121
CVE-2024-9121
PUBLISHED
In Google Chrome und Microsoft Edge bestehen mehrere Schwachstellen. Diese Fehler existieren in den V8-, Dawn- und Skia-Komponenten, die durch eine Use-after-free-, eine Typverwechslung, eine unangemessene Implementierung und einen Integer-Überlauf verursacht werden, was zu einer entfernten Codeausführung führen kann. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um nicht spezifizierte Auswirkungen zu verursachen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 0.40% · 60.9th percentile
Risk Scores
EPSS Score
0.40%
60.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE | SUSE openSUSE | |
| Microsoft | Microsoft Edge Extended <128.0.2739.97 | |
| Microsoft | Microsoft Edge <129.0.2792.65 | |
| Google Chrome <129.0.6668.71 | ||
| Debian | Debian Linux | |
| Google Chrome <129.0.6668.70 | ||
| Fedora | Fedora Linux |
Exploit Intelligence
- https://issues.chromium.org/issues/363538434 (nist-nvd)
Timeline
- Sep 24, 2024 CVE Published
- Sep 25, 2024 EPSS Score
- Sep 26, 2024 CVE Updated
- Oct 5, 2024 Coalition ESS Score
- Oct 14, 2024 EPSS Score
- Nov 3, 2024 EPSS Score
- Nov 22, 2024 EPSS Score
- Dec 12, 2024 EPSS Score
- Jan 1, 2025 EPSS Score
- Jan 20, 2025 EPSS Score
- Jan 21, 2025 Coalition ESS Score
- Feb 8, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2216.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-2216 advisory
- https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-89511748af advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-aaff7345b8 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-e60359f212 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-5ec6a4bb83 advisory
- https://lists.debian.org/debian-security-announce/2024/msg00188.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-8008ddbd4e advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/XUWTKZIDZ3ME45LREUL2P3MDUEBKCPKD/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/7W47GCQGZBSTBR3B5U5BWO6LTDL47WPU/ advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-26-2024 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/PSCMNKOFIFR6UW562BL6G3POOMLBOVMN/ advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-a3d9061962 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-ae299cc269 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-452b60addf advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-7aba3c1531 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GYIF7RESU4PKGREHH5YVHUYYGB57P4CQ/ advisory