8.8
CVSSv3

CVE-2021-30560

Published: 03/08/2021 Updated: 27/03/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use after free in Blink XSLT in Google Chrome before 91.0.4472.164 allowed a remote malicious user to potentially exploit heap corruption via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

xmlsoft libxslt

debian debian linux 10.0

debian debian linux 11.0

splunk universal forwarder 9.1.0

splunk universal forwarder

Vendor Advisories

Several security issues were fixed in Libxslt ...
Several security issues were fixed in Libxslt ...
Nick Wellnhofer discovered that the xsltApplyTemplates function in libxslt, an XSLT processing runtime library, is prone to a use-after-free flaw, resulting in a denial of service, or potentially the execution of arbitrary code if a specially crafted file is processed For the stable distribution (bullseye), this problem has been fixed in version 1 ...
A use after free security issue has been found in the Blink XSLT component of the Chromium browser engine before version 9104472164 ...
LTC-102 has been updated in the LTC (Long Term Support Candidate) channel to 10205005153 (Platform Version: 146951140) for most ChromeOS devices Want to know more about Long-term Support? Click here This update includes the following Security fixes:1335458  Critical  CVE-2022-2156   Use ...
The Stable channel has been updated to 9104472164 for Windows, Mac and Linux which will roll out over the coming days/weeksA full list of changes in this build is available in the log Interested in switching release channels?  Find out how here If you find a new issue, please let us know by filing a bug The community help forum is also ...
LTS-96 has been updated in the LTS channel to 9604664215 (Platform Version: 14268940) for most ChromeOS devices Want to know more about Long-term Support? Click here This update includes the following Security fixes:1325298  High  CVE-2022-2010  Out of bounds read in compositing1302959 & ...