Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:NMicrosoft Edge
APPMicrosoft< 140.0.3485.71
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Powiązane podatności
CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓ten sam produkt
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
CVE-2022-4135CRITICAL9.6⚠ KEVPL ✓ten sam produkt
Heap buffer overflow w GPU w Google Chrome — sandbox escape
CVE-2015-0313CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Use-after-free w Adobe Flash Player umożliwiający RCE
CVE-2015-0311CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Adobe Flash Player — aktywnie exploitowana podatność 0-day
CVE-2019-0938CRITICAL9.0PL ✓ten sam produkt
Microsoft Edge — privilege escalation poprzez ucieczkę z sandbox AppContainer