Debian ha rilasciato aggiornamenti per gst-plugins-base1.0 che correggono un integer overflow nel RIFF parser di GStreamer (CVE-2026-2921). Un file multimediale malformato può causare denial of service o potenzialmente l'esecuzione di codice arbitrario se aperto.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 33% (97º percentile). Patch Microsoft: Release Notes.
Data di correzione federale CISA 27 mar
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 23% (96º percentile). Patch Microsoft: Release Notes.
Data di correzione federale CISA 27 mar