Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
References
Link | Resource |
---|---|
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html | Release Notes Vendor Advisory |
https://crbug.com/1219209 | Issue Tracking Patch Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2022/09/msg00010.html | Mailing List Third Party Advisory |
https://security.gentoo.org/glsa/202310-23 | Third Party Advisory |
https://www.debian.org/security/2022/dsa-5216 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
27 Mar 2024, 14:45
Type | Values Removed | Values Added |
---|---|---|
First Time |
Splunk universal Forwarder
Splunk |
|
References | () https://security.gentoo.org/glsa/202310-23 - Third Party Advisory | |
CPE | cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:* cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* |
27 Oct 2022, 20:10
Type | Values Removed | Values Added |
---|---|---|
References | (DEBIAN) https://www.debian.org/security/2022/dsa-5216 - Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2022/09/msg00010.html - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
09 Sep 2022, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Aug 2022, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 May 2022, 15:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* | |
References | (MISC) https://crbug.com/1219209 - Issue Tracking, Patch, Vendor Advisory |
09 Aug 2021, 16:42
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.8 |
References | (MISC) https://crbug.com/1219209 - Permissions Required, Vendor Advisory | |
References | (MISC) https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html - Release Notes, Vendor Advisory | |
CWE | CWE-416 |
03 Aug 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-03 19:15
Updated : 2024-03-27 14:45
NVD link : CVE-2021-30560
Mitre link : CVE-2021-30560
CVE.ORG link : CVE-2021-30560
JSON object : View
Products Affected
xmlsoft
- libxslt
splunk
- universal_forwarder
debian
- debian_linux
- chrome
CWE
CWE-416
Use After Free