Vulnerabilità · 196 giorni fa

Debian Risolve Integer Overflow nel RIFF Parser di GStreamer

Debian ha rilasciato aggiornamenti per gst-plugins-base1.0 che correggono un integer overflow nel RIFF parser di GStreamer (CVE-2026-2921). Un file multimediale malformato può causare denial of service o potenzialmente l'esecuzione di codice arbitrario se aperto.

CVE-2026-3909

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 33% (97º percentile). Patch Microsoft: Release Notes.

Data di correzione federale CISA 27 mar

CVE-2026-3910

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 23% (96º percentile). Patch Microsoft: Release Notes.

Data di correzione federale CISA 27 mar

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-03-24

Editions

Storie correlate