CVE-2024-3174
published 2024-07-16CVE-2024-3174: Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.36%
29.1th percentile
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 119.0.6045.105-1~deb11u1 | 119.0.6045.105-1~deb11u1 |
| chromium | chromium | >= 0 < 119.0.6045.105-1~deb12u1 | 119.0.6045.105-1~deb12u1 |
| chromium | chromium | >= 0 < 119.0.6045.105-1 | 119.0.6045.105-1 |
| chromium | chromium | >= 0 < 119.0.6045.105-1 | 119.0.6045.105-1 |
| debian | chromium | < chromium 119.0.6045.105-1~deb12u1 (bookworm) | chromium 119.0.6045.105-1~deb12u1 (bookworm) |
| chrome | < 119.0.6045.105 | 119.0.6045.105 | |
| chrome | >= 119.0.6045.105 < 119.0.6045.105 | 119.0.6045.105 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qw4m-qq5c-43c6: Inappropriate implementation in V8 in Google Chrome prior to 119
ghsa_unreviewed·2024-07-17
CVE-2024-3174 [HIGH] CWE-79 GHSA-qw4m-qq5c-43c6: Inappropriate implementation in V8 in Google Chrome prior to 119
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2024-3174: Inappropriate implementation in V8 in Google Chrome prior to 119
osv·2024-07-16·CVSS 8.8
CVE-2024-3174 [HIGH] CVE-2024-3174: Inappropriate implementation in V8 in Google Chrome prior to 119
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Red Hat
kernel: perf/x86/intel: Limit the period on Haswell
vendor_redhat·2024-09-27·CVSS 5.5
CVE-2024-46848 [MEDIUM] CWE-754 kernel: perf/x86/intel: Limit the period on Haswell
kernel: perf/x86/intel: Limit the period on Haswell
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/intel: Limit the period on Haswell
Running the ltp test cve-2015-3290 concurrently reports the following
warnings.
perfevents: irq loop stuck!
WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174
intel_pmu_handle_irq+0x285/0x370
Call Trace:
? __warn+0xa4/0x220
? intel_pmu_handle_irq+0x285/0x370
? __report_bug+0x123/0x130
? intel_pmu_handle_irq+0x285/0x370
? __report_bug+0x123/0x130
? intel_pmu_handle_irq+0x285/0x370
? report_bug+0x3e/0xa0
? handle_bug+0x3c/0x70
? exc_invalid_op+0x18/0x50
? asm_exc_invalid_op+0x1a/0x20
? irq_work_claim+0x1e/0x40
? intel_pmu_handle_irq+0x285/0x370
perf_event_nmi_handler+0x3d/0x60
nmi_handle+0x104/0x330
Thanks to Thoma
Debian
CVE-2024-3174: chromium - Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allo...
vendor_debian·2024·CVSS 8.8
CVE-2024-3174 [HIGH] CVE-2024-3174: chromium - Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allo...
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1)
forky: resolved (fixed in 119.0.6045.105-1)
sid: resolved (fixed in 119.0.6045.105-1)
trixie: resolved (fixed in 119.0.6045.105-1)
Chrome
Stable Channel Update for Desktop: CVE-2024-3174
vendor_chrome·2023-10-31·CVSS 4.3
CVE-2024-3174 [HIGH] Stable Channel Update for Desktop: CVE-2024-3174
Stable Channel Update for Desktop
CVE-2024-3174: Inappropriate implementation in V8. Reported by Alan Goodman on 2023-09-25 [$3000][ 1281972 ] Medium CVE-2023-5850: Incorrect security UI in Downloads
Reported by Mohit Raj (shadow2639) on 2021-12-22 [$5000][ 40066780 ] Medium CVE-2023-7011: Inappropriate implementation in Picture in Picture
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-16
Published