vulnerability

FreeBSD: VID-48514901-711D-11EB-9846-E09467587C17 (CVE-2021-21152): chromium -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
2021-02-16
Added
2021-02-18
Modified
2021-03-08

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-48514901-711D-11EB-9846-E09467587C17:




Chrome Releases reports:



This release contains 10 security fixes, including:



[1138143] High CVE-2021-21149: Stack overflow in Data Transfer.


Reported by Ryoya Tsukasaki on 2020-10-14


[1172192] High CVE-2021-21150: Use after free in Downloads.


Reported by Woojin Oh(@pwn_expoit) of STEALIEN on 2021-01-29


[1165624] High CVE-2021-21151: Use after free in Payments.


Reported by Khalil Zhani on 2021-01-12


[1166504] High CVE-2021-21152: Heap buffer overflow in Media.


Reported by Anonymous on 2021-01-14


[1155974] High CVE-2021-21153: Stack overflow in GPU Process.


Reported by Jan Ruge of ERNW GmbH on 2020-12-06


[1173269] High CVE-2021-21154: Heap buffer overflow in Tab


Strip. Reported by Abdulrahman Alqabandi, Microsoft Browser


Vulnerability Research on 2021-02-01


[1175500] High CVE-2021-21155: Heap buffer overflow in Tab


Strip. Reported by Khalil Zhani on 2021-02-07


[1177341] High CVE-2021-21156: Heap buffer overflow in V8.


Reported by Sergei Glazunov of Google Project Zero on


2021-02-11


[1170657] Medium CVE-2021-21157: Use after free in Web


Sockets. Reported by Anonymous on 2021-01-26





Solution

freebsd-upgrade-package-chromium
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.