Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-E0914087-9A09-11EC-9E61-3065EC8FD3EC (CVE-2022-0801): chromium -- multiple vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-E0914087-9A09-11EC-9E61-3065EC8FD3EC (CVE-2022-0801): chromium -- multiple vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
03/01/2022
Created
11/08/2022
Added
11/04/2022
Modified
01/12/2023

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From VID-E0914087-9A09-11EC-9E61-3065EC8FD3EC:

Chrome Releases reports:

This release contains 28 security fixes, including:

[1289383] High CVE-2022-0789: Heap buffer overflow in ANGLE.

Reported by SeongHwan Park (SeHwa) on 2022-01-21

[1274077] High CVE-2022-0790: Use after free in Cast UI.

Reported by Anonymous on 2021-11-26

[1278322] High CVE-2022-0791: Use after free in Omnibox.

Reported by Zhihua Yao of KunLun Lab on 2021-12-09

[1285885] High CVE-2022-0792: Out of bounds read in ANGLE.

Reported by Jaehun Jeong (@n3sk) of Theori on 2022-01-11

[1291728] High CVE-2022-0793: Use after free in Views. Reported

by Thomas Orlita on 2022-01-28

[1294097] High CVE-2022-0794: Use after free in WebShare.

Reported by Khalil Zhani on 2022-02-04

[1282782] High CVE-2022-0795: Type Confusion in Blink Layout.

Reported by 0x74960 on 2021-12-27

[1295786] High CVE-2022-0796: Use after free in Media. Reported

by Cassidy Kim of Amber Security Lab, OPPO Mobile

Telecommunications Corp. Ltd. on 2022-02-10

[1281908] High CVE-2022-0797: Out of bounds memory access in

Mojo. Reported by Sergei Glazunov of Google Project Zero on

2021-12-21

[1283402] Medium CVE-2022-0798: Use after free in MediaStream.

Reported by Samet Bekmezci @sametbekmezci on 2021-12-30

[1279188] Medium CVE-2022-0799: Insufficient policy enforcement

in Installer. Reported by Abdelhamid Naceri (halov) on

2021-12-12

[1242962] Medium CVE-2022-0800: Heap buffer overflow in Cast UI.

Reported by Khalil Zhani on 2021-08-24

[1231037] Medium CVE-2022-0801: Inappropriate implementation in

HTML parser. Reported by Michal Bentkowski of Securitum on

2021-07-20

[1270052] Medium CVE-2022-0802: Inappropriate implementation in

Full screen mode. Reported by Irvan Kurniawan (sourc7) on

2021-11-14

[1280233] Medium CVE-2022-0803: Inappropriate implementation in

Permissions. Reported by Abdulla Aldoseri on 2021-12-15

[1264561] Medium CVE-2022-0804: Inappropriate implementation in

Full screen mode. Reported by Irvan Kurniawan (sourc7) on

2021-10-29

[1290700] Medium CVE-2022-0805: Use after free in Browser

Switcher. Reported by raven at KunLun Lab on 2022-01-25

[1283434] Medium CVE-2022-0806: Data leak in Canvas. Reported by

Paril on 2021-12-31

[1287364] Medium CVE-2022-0807: Inappropriate implementation in

Autofill. Reported by Alesandro Ortiz on 2022-01-14

[1292271] Medium CVE-2022-0808: Use after free in Chrome OS

Shell. Reported by @ginggilBesel on 2022-01-29

[1293428] Medium CVE-2022-0809: Out of bounds memory access in

WebXR. Reported by @uwu7586 on 2022-02-03

Solution(s)

  • freebsd-upgrade-package-chromium

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;