CVE-2021-38003

Hoch8.8Veröffentlicht am 23. November 2021

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Aktiv ausgenutzt

  • Seit dem 3. Nov. 2021 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 17. Nov. 2021 beheben (BOD 22-01)
  • Angegriffen 29 Tage bevor die Schwachstelle öffentlich wurde

Apply updates per vendor instructions.

Quelle: CISA KEV · 3. Dez. 2025 6. Feb. 2024 25. Mai 2023 10. Feb. 2023 3. Nov. 2021 26. Okt. 2021

CVSS-Score8.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-755, CWE-755
Herstellerdebian, fedoraproject, google

Betroffene Produkte

HerstellerProduktVersionen
googlechrome< 95.0.4638.69
fedoraprojectfedora34
debiandebian linux10.0

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank