vulnerability

FreeBSD: VID-48514901-711D-11EB-9846-E09467587C17 (CVE-2021-21152): chromium -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Feb 16, 2021
Added
Feb 18, 2021
Modified
Mar 8, 2021

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-48514901-711D-11EB-9846-E09467587C17:




Chrome Releases reports:



This release contains 10 security fixes, including:



[1138143] High CVE-2021-21149: Stack overflow in Data Transfer.


Reported by Ryoya Tsukasaki on 2020-10-14


[1172192] High CVE-2021-21150: Use after free in Downloads.


Reported by Woojin Oh(@pwn_expoit) of STEALIEN on 2021-01-29


[1165624] High CVE-2021-21151: Use after free in Payments.


Reported by Khalil Zhani on 2021-01-12


[1166504] High CVE-2021-21152: Heap buffer overflow in Media.


Reported by Anonymous on 2021-01-14


[1155974] High CVE-2021-21153: Stack overflow in GPU Process.


Reported by Jan Ruge of ERNW GmbH on 2020-12-06


[1173269] High CVE-2021-21154: Heap buffer overflow in Tab


Strip. Reported by Abdulrahman Alqabandi, Microsoft Browser


Vulnerability Research on 2021-02-01


[1175500] High CVE-2021-21155: Heap buffer overflow in Tab


Strip. Reported by Khalil Zhani on 2021-02-07


[1177341] High CVE-2021-21156: Heap buffer overflow in V8.


Reported by Sergei Glazunov of Google Project Zero on


2021-02-11


[1170657] Medium CVE-2021-21157: Use after free in Web


Sockets. Reported by Anonymous on 2021-01-26





Solution

freebsd-upgrade-package-chromium
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.