CVE-2024-3175
published 2024-07-16CVE-2024-3175: Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted…
PriorityP431medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.23%
14.2th percentile
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 120.0.6099.71-1~deb11u1 | 120.0.6099.71-1~deb11u1 |
| chromium | chromium | >= 0 < 120.0.6099.71-1~deb12u1 | 120.0.6099.71-1~deb12u1 |
| chromium | chromium | >= 0 < 120.0.6099.71-1 | 120.0.6099.71-1 |
| chromium | chromium | >= 0 < 120.0.6099.71-1 | 120.0.6099.71-1 |
| debian | chromium | < chromium 120.0.6099.71-1~deb12u1 (bookworm) | chromium 120.0.6099.71-1~deb12u1 (bookworm) |
| chrome | < 120.0.6099.62 | 120.0.6099.62 | |
| chrome | >= 120.0.6099.62 < 120.0.6099.62 | 120.0.6099.62 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-3175: chromium - Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099....
vendor_debian·2024·CVSS 6.3
CVE-2024-3175 [MEDIUM] CVE-2024-3175: chromium - Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099....
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1)
forky: resolved (fixed in 120.0.6099.71-1)
sid: resolved (fixed in 120.0.6099.71-1)
trixie: resolved (fixed in 120.0.6099.71-1)
Chrome
Stable Channel Update for Desktop: CVE-2023-6510
vendor_chrome·2023-12-05·CVSS 8.8
CVE-2023-6510 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-6510
Stable Channel Update for Desktop
CVE-2023-6510: Use after free in Media Capture. Reported by [pwn2car] on 2023-09-08 [$2000][ 1478613 ] Low CVE-2023-6511: Inappropriate implementation in Autofill
Reported by Ahmed ElMasry on 2023-09-04 [$5000][ 40069571 ] Low CVE-2024-3175: Insufficient data validation in Extensions
Severity: medium
GHSA
GHSA-38cc-8h76-38hf: Insufficient data validation in Extensions in Google Chrome prior to 120
ghsa_unreviewed·2024-07-17
CVE-2024-3175 [MEDIUM] CWE-1287 GHSA-38cc-8h76-38hf: Insufficient data validation in Extensions in Google Chrome prior to 120
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
OSV
CVE-2024-3175: Insufficient data validation in Extensions in Google Chrome prior to 120
osv·2024-07-16·CVSS 6.3
CVE-2024-3175 [MEDIUM] CVE-2024-3175: Insufficient data validation in Extensions in Google Chrome prior to 120
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
Suricata
ET WEB_SPECIFIC_APPS W2B Online Banking SQL Injection Attempt -- DocPay.w2b listDocPay ASCII
suricata·2010-07-30
CVE-2007-3175 ET WEB_SPECIFIC_APPS W2B Online Banking SQL Injection Attempt -- DocPay.w2b listDocPay ASCII
ET WEB_SPECIFIC_APPS W2B Online Banking SQL Injection Attempt -- DocPay.w2b listDocPay ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS W2B Online Banking SQL Injection Attempt -- DocPay.w2b listDocPay ASCII"; flow:established,to_server; http.uri; content:"/DocPay.w2b?"; nocase; content:"listDocPay="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,2007-3175; reference:url,xforce.iss.net/xforce/xfdb/34593; classtype:web-application-attack; sid:2005190; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2024_01_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access,
No public exploits indexed.
No writeups or analysis indexed.
2024-07-16
Published