CVE-2018-18339
- EPSS 1.5%
- Published 11.12.2018 16:29:00
- Last modified 21.11.2024 03:55:44
Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-6095
- EPSS 0.97%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:03
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
CVE-2018-6116
- EPSS 1.57%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:06
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2018-6108
- EPSS 0.95%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:05
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.
CVE-2018-6107
- EPSS 0.95%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:04
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2018-6105
- EPSS 0.95%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:04
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2018-6104
- EPSS 0.95%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:04
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2018-6103
- EPSS 0.65%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:04
A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.
CVE-2018-6102
- EPSS 0.95%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:04
Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2018-6101
- EPSS 2.11%
- Published 04.12.2018 17:29:01
- Last modified 21.11.2024 04:10:04
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.