Aller au contenu
Appaloosa Scout
HIGH 8.8 KEV

CVE-2023-4863

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2023-09-13
Deadline remédiation
2023-10-04
Action requise
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
google chrome Android <116.0.5845.187 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
google chrome iOS <116.0.5845.187 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
mozilla firefox Android <102.15.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla firefox iOS <102.15.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla firefox Android <117.0.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
mozilla firefox iOS <117.0.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
mozilla firefox Android ≥115.1.0 <115.2.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla firefox iOS ≥115.1.0 <115.2.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
microsoft teams Android <1.6.00.26474 cpe:2.3:a:microsoft:teams:*:*:*:*:desktop:*:*:*
microsoft teams iOS <1.6.00.26474 cpe:2.3:a:microsoft:teams:*:*:*:*:desktop:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗