CVE-2023-1220
published 2023-03-07CVE-2023-1220: Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.12%
62.8th percentile
Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aimeos | ai-admin-graphql | >= 2022.04.1 < 2022.10.10 | 2022.10.10 |
| aimeos | ai-admin-graphql | >= 2023.04.1 < 2023.10.6 | 2023.10.6 |
| aimeos | ai-admin-graphql | >= 2024.04.1 < 2024.04.6 | 2024.04.6 |
| aimeos | ai-admin-graphql | >= 2024.04.1 < 2024.04.2 | 2024.04.2 |
| chromium | chromium | >= 0 < 111.0.5563.64-1~deb11u1 | 111.0.5563.64-1~deb11u1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| debian | chromium | < chromium 111.0.5563.64-1 (bookworm) | chromium 111.0.5563.64-1 (bookworm) |
| chrome | < 111.0.5563.64 | 111.0.5563.64 | |
| chrome | >= 111.0.5563.64 < 111.0.5563.64 | 111.0.5563.64 | |
| chrome_chrome | — | — | |
| miniflux.app | v2 | >= 0 < 2.0.43 | 2.0.43 |
| msrc | cbl2_ceph_16.2.10-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | microsoft_edge | — | — |
| msrc | microsoft_edge_extended_stable | — | — |
| msrc | microsoft_visual_studio_2022_version_17.0 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.2 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.4 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.6 | — | — |
| msrc | net_6.0 | — | — |
| msrc | net_7.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: mac80211_hwsim: drop short frames
vendor_redhat·2025-09-16·CVSS 7.1
CVE-2023-53321 [HIGH] CWE-1220 kernel: wifi: mac80211_hwsim: drop short frames
kernel: wifi: mac80211_hwsim: drop short frames
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: drop short frames
While technically some control frames like ACK are shorter and
end after Address 1, such frames shouldn't be forwarded through
wmediumd or similar userspace, so require the full 3-address
header to avoid accessing invalid memory if shorter frames are
passed in.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Package
Microsoft
IBM Spectrum Fusion HCI improper access control
vendor_msrc·2024-05-14·CVSS 6.5
CVE-2023-43040 [MEDIUM] CWE-1220 IBM Spectrum Fusion HCI improper access control
IBM Spectrum Fusion HCI improper access control
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
ibm: ibm
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.c
Red Hat
tripleo-ansible: bind keys are world readable
vendor_redhat·2024-03-15·CVSS 5.5
CVE-2023-6725 [MEDIUM] CWE-1220 tripleo-ansible: bind keys are world readable
tripleo-ansible: bind keys are world readable
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
Package: openstack-designate (Red Hat OpenStack Platform 16.1) - Not affected
Package: openstack-designate (Red Hat OpenStack Platform 16.2) - Not affected
Package: openstack-design
Red Hat
open-vm-tools: SAML token signature bypass
vendor_redhat·2023-10-26·CVSS 7.1
CVE-2023-34058 [HIGH] CWE-1220 open-vm-tools: SAML token signature bypass
open-vm-tools: SAML token signature bypass
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
A flaw was found in open-vm-tools. This flaw allows a malicious actor that has been granted Guest Operation Privileges in a target virtual machine to elevate their privileges if that target virtual
Red Hat
openshift-logging: LokiStack authorisation is cached too broadly
vendor_redhat·2023-08-21·CVSS 5.7
CVE-2023-4456 [MEDIUM] CWE-1220 openshift-logging: LokiStack authorisation is cached too broadly
openshift-logging: LokiStack authorisation is cached too broadly
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.
Red Hat
postgresql: MERGE fails to enforce UPDATE or SELECT row security policies
vendor_redhat·2023-08-10·CVSS 3.1
CVE-2023-39418 [LOW] CWE-1220 postgresql: MERGE fails to enforce UPDATE or SELECT row security policies
postgresql: MERGE fails to enforce UPDATE or SELECT row security policies
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
Statement: This vulnerability introduced with the use of MERGE Command in PostgreSQL 15 and only affects the databases that have used CREATE POLICY to define a row
sec
Microsoft
.NET and Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2023-07-11·CVSS 8.1
CVE-2023-33127 [HIGH] CWE-1220 .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
The attacker would gain the rights of the user that is running the affected application.
FAQ: According to the CVSS metric, the attack vector is network (AV:N). How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by abusing the .NET diagnostics server to gain elevation of privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition and also to take additional actions prior to exploitation to prepare the target environment.
.NET and
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-1220
vendor_chrome·2023-03-24·CVSS 8.8
CVE-2023-1220 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2023-1220
Long Term Support Channel Update for ChromeOS
CVE-2023-1220
Microsoft
Chromium: CVE-2023-1220 Heap buffer overflow in UMA
vendor_msrc·2023-03-14·CVSS 8.8
CVE-2023-1220 [HIGH] Chromium: CVE-2023-1220 Heap buffer overflow in UMA
Chromium: CVE-2023-1220 Heap buffer overflow in UMA
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
FAQ: W
Ubuntu
Chromium vulnerabilities
vendor_ubuntu·2023-03-13·CVSS 8.8
CVE-2023-1213 [HIGH] Chromium vulnerabilities
Title: Chromium vulnerabilities
Summary: Several security issues were fixed in Chromium.
It was discovered that Chromium could be made to write out of bounds in
several components. A remote attacker could possibly use this issue to
corrupt memory via a crafted HTML page, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2023-0930, CVE-2023-1219,
CVE-2023-1220, CVE-2023-1222)
It was discovered that Chromium contained an integer overflow in the PDF
component. A remote attacker could possibly use this issue to corrupt
memory via a crafted PDF file, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2023-0933)
It was discovered that Chromium did not properly manage memory in several
components. A remote attacker could possibly use this issue
Debian
CVE-2023-1220: chromium - Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a re...
vendor_debian·2023·CVSS 8.8
CVE-2023-1220 [HIGH] CVE-2023-1220: chromium - Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a re...
Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: resolved (fixed in 111.0.5563.64-1)
trixie: resolved (fixed in 111.0.5563.64-1)
GHSA
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
ghsa·2025-04-02
CVE-2023-27591 [HIGH] CWE-1220 Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
### Impact
An unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` [configuration option](https://miniflux.app/docs/configuration.html#metrics-collector) is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the default).
### Patches
PR #1745 fixes the problem. Available in Miniflux >= 2.0.43.
### Workarounds
Set `METRICS_COLLECTOR` to `false` (default) or run Miniflux behind a trusted reverse-proxy.
### References
- https://miniflux.app/docs/configuration.html#metrics-collector
- https://miniflux.app/docs/configuration.html#metrics-allowed-networks
GHSA
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
ghsa·2024-07-02
CVE-2024-39323 [HIGH] CWE-1220 aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue.
GHSA
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
ghsa·2024-07-02
CVE-2024-39324 [LOW] CWE-1220 aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue.
GHSA
Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability
ghsa·2023-07-11·CVSS 8.1
CVE-2023-33127 [HIGH] CWE-1220 Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET applications where the diagnostic server can be exploited to achieve cross-session/cross-user elevation of privilege (EoP) and code execution.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/263
### Mitigation factors
Microsoft has not identified any mitigating factors
OSV
chromium-browser vulnerabilities
osv·2023-03-13·CVSS 8.8
CVE-2023-0930 [HIGH] chromium-browser vulnerabilities
chromium-browser vulnerabilities
It was discovered that Chromium could be made to write out of bounds in
several components. A remote attacker could possibly use this issue to
corrupt memory via a crafted HTML page, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2023-0930, CVE-2023-1219,
CVE-2023-1220, CVE-2023-1222)
It was discovered that Chromium contained an integer overflow in the PDF
component. A remote attacker could possibly use this issue to corrupt
memory via a crafted PDF file, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2023-0933)
It was discovered that Chromium did not properly manage memory in several
components. A remote attacker could possibly use this issue to corrupt
memory via a crafted HTML page, resulting in
GHSA
GHSA-j2jf-89hq-7g58: Heap buffer overflow in UMA in Google Chrome prior to 111
ghsa_unreviewed·2023-03-08
CVE-2023-1220 [HIGH] CWE-787 GHSA-j2jf-89hq-7g58: Heap buffer overflow in UMA in Google Chrome prior to 111
Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2023-1220: Heap buffer overflow in UMA in Google Chrome prior to 111
osv·2023-03-07·CVSS 8.8
CVE-2023-1220 [HIGH] CVE-2023-1220: Heap buffer overflow in UMA in Google Chrome prior to 111
Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/171796/Chrome-base-SampleVectorBase-MoveSingleSampleToCounts-Heap-Buffer-Overflow.htmlhttps://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.htmlhttps://crbug.com/1417185http://packetstormsecurity.com/files/171796/Chrome-base-SampleVectorBase-MoveSingleSampleToCounts-Heap-Buffer-Overflow.htmlhttps://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.htmlhttps://crbug.com/1417185
2023-03-07
Published