Severity
9.8CRITICALNVD
EPSS
1.0%
top 23.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateDec 10

Description

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/chrome121.0.6167.160121.0.6167.160
NVDgoogle/chrome< 121.0.6167.160
Debianchromium/chromium< 121.0.6167.160-1~deb12u1+2
PyPIdjangoproject/django5.05.0.8+1

Also affects: Fedora 38, 39

🔴Vulnerability Details

5
GHSA
Django vulnerable to denial-of-service attack2024-08-07
GHSA
panic on parsing crafted phonenumber inputs2024-07-09
GHSA
GHSA-pf89-rhhw-xmhp: Use after free in Mojo in Google Chrome prior to 1212024-02-07
OSV
CVE-2024-1284: Use after free in Mojo in Google Chrome prior to 1212024-02-07
CVEList
CVE-2024-1284: Use after free in Mojo in Google Chrome prior to 1212024-02-06

📋Vendor Advisories

9
Microsoft
netdevsim: prevent bad user input in nsim_dev_health_break_write()2024-12-10
Microsoft
Unbounded name compression could lead to Denial of Service2024-10-08
Red Hat
NVIDIA CUDA Toolkit: Denial of service in NVIDIA CUDA2024-08-31
Red Hat
OpenJDK: Pack200 increase loading time due to improper header validation (8322106)2024-07-16
Microsoft
Bluetooth: L2CAP: Fix not validating setsockopt user input2024-05-14

🕵️Threat Intelligence

5
Bleepingcomputer
Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws2024-02-13
Trendmicro
The February 2024 Security Update Review2024-02-12
Trendmicro
The February 2024 Security Update Review2024-02-12
Trendmicro
The February 2024 Security Update Review2024-02-12
Trendmicro
The February 2024 Security Update Review2024-02-12
CVE-2024-1284 — Use After Free in Google Chrome | cvebase