CVE-2021-38003

Alta8.8Pubblicata il 23 novembre 2021

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 3 nov 2021
  • Le agenzie federali statunitensi devono correggerla entro il 17 nov 2021 (direttiva BOD 22-01)
  • Attaccata 29 giorni prima che la vulnerabilità fosse resa pubblica

Apply updates per vendor instructions.

Fonte: CISA KEV · 3 dic 2025 6 feb 2024 25 mag 2023 10 feb 2023 3 nov 2021 26 ott 2021

Punteggio CVSS8.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-755, CWE-755
Vendordebian, fedoraproject, google

Prodotti coinvolti

VendorProdottoVersioni
googlechrome< 95.0.4638.69
fedoraprojectfedora34
debiandebian linux10.0

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE