CVE-2024-21639
Description
CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory
does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit 1f55d2e.
- CVSS Version 3.1
nvd
CVE ID: CVE-2024-21639
Base Score: 9.6
Base Severity: CRITICAL
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Impact Score: 5.8
Exploitability Score: 3.1
github
CVE ID: CVE-2024-21639
Base Score: 5.3
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.6