Showing 6 vulnerabilities on this page for CefSharp.Wpf.HwndHost

Signals CISA KEV Ransomware Nuclei
NuGet vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) https://nvd.nist.gov/vuln/detail/CVE-2025-2783 https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html https://issues.chromium.org/issues/405143032

Apr 12, 2025
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use after free in Animation

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CWE-416Apr 4, 2022
CVSS8.8v3.1EPSS20.8%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Use after free in CefSharp

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CWE-416Jan 8, 2021
CVSS9.6v3.1EPSS2.75%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Inappropriate implementation in V8 in CefSharp

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CWE-119CWE-787Jan 8, 2021
CVSS8.8v3.1EPSS2.83%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Inappropriate implementation in V8

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CWE-787CWE-843Nov 3, 2020
CVSS8.8v3.1EPSS48.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Heap buffer overflow in CefSharp

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS9.6v3.1EPSS44.3%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX