CVE-2022-4919
published 2023-07-29CVE-2022-4919: Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.55%
42.2th percentile
Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 101.0.4951.41-1~deb11u1 | 101.0.4951.41-1~deb11u1 |
| chromium | chromium | >= 0 < 101.0.4951.41-1 | 101.0.4951.41-1 |
| chromium | chromium | >= 0 < 101.0.4951.41-1 | 101.0.4951.41-1 |
| chromium | chromium | >= 0 < 101.0.4951.41-1 | 101.0.4951.41-1 |
| debian | chromium | < chromium 101.0.4951.41-1 (bookworm) | chromium 101.0.4951.41-1 (bookworm) |
| chrome | < 101.0.4951.41 | 101.0.4951.41 | |
| chrome | >= 101.0.4951.41 < 101.0.4951.41 | 101.0.4951.41 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67q3-2pr7-fh4j: Use after free in Base Internals in Google Chrome prior to 101
ghsa_unreviewed·2023-07-29
CVE-2022-4919 [HIGH] CWE-416 GHSA-67q3-2pr7-fh4j: Use after free in Base Internals in Google Chrome prior to 101
Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2022-4919: Use after free in Base Internals in Google Chrome prior to 101
osv·2023-07-29·CVSS 8.8
CVE-2022-4919 [HIGH] CVE-2022-4919: Use after free in Base Internals in Google Chrome prior to 101
Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Red Hat
vim: heap buffer overflow in vim_strncpy
vendor_redhat·2022-05-10·CVSS 7.8
CVE-2022-1621 [HIGH] CWE-787 vim: heap buffer overflow in vim_strncpy
vim: heap buffer overflow in vim_strncpy
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
A flaw was found in vim, where it is vulnerable to a heap buffer overflow in the vim_strncpy find_word function. This flaw allows a specially crafted file to crash software, modify memory and possibly perform remote execution when opened in vim.
Package: vim (Red Hat Enterprise Linux 6) - Out of support scope
Package: vim (Red Hat Enterprise Linux 7) - Out of support scope
Chrome
Stable Channel Update for Desktop: CVE-2022-4919
vendor_chrome·2022-04-26·CVSS 6.5
CVE-2022-4919 [HIGH] Stable Channel Update for Desktop: CVE-2022-4919
Stable Channel Update for Desktop
CVE-2022-4919: Use after free in Base Internals. Reported by Sri on 2022-04-01 [$NA][ 1304987 ] High CVE-2022-1482: Inappropriate implementation in WebGL
Reported by Christoph Diehl, Microsoft on 2022-03-10 [$NA][ 1314754 ] High CVE-2022-1483: Heap buffer overflow in WebGPU
Severity: high
Debian
CVE-2022-4919: chromium - Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed...
vendor_debian·2022·CVSS 8.8
CVE-2022-4919 [HIGH] CVE-2022-4919: chromium - Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed...
Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
trixie: resolved (fixed in 101.0.4951.41-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.htmlhttps://crbug.com/1312450https://lists.fedoraproject.org/archives/list/[email protected]/message/PQKT7EGDD2P3L7S3NXEDDRCPK4NNZNWJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/YKLJ3B3D5BCVWE3QNP4N7HHF26OHD567/https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.htmlhttps://crbug.com/1312450https://lists.fedoraproject.org/archives/list/[email protected]/message/PQKT7EGDD2P3L7S3NXEDDRCPK4NNZNWJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/YKLJ3B3D5BCVWE3QNP4N7HHF26OHD567/
2023-07-29
Published