CVE-2015-5237High· 8.8▾ Twilightprotobuf susceptible to buffer overflow
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
5.1%
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
Google.Protobuf < 3.4.0com.google.protobuf:protobuf-parent < 3.4.0github.com/protocolbuffers/protobuf < 3.4.0google/protobuf < 3.4.0protobuf < 3.4.0Upgrade to a patched release:
Google.Protobuf 3.4.0com.google.protobuf:protobuf-parent 3.4.0github.com/protocolbuffers/protobuf 3.4.0google/protobuf 3.4.0protobuf 3.4.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93387Medium· 4.3Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
CVE-2026-93386Medium· 5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page
CVE-2026-93385Medium· 6.5Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page
CVE-2026-93384Low· 3.7Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic
CVE-2026-93383Medium· 4.3Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page
CVE-2026-93382High· 8.8Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page