CVE-2017-15411
- EPSS 0.94%
- Published 28.08.2018 19:29:04
- Last modified 21.11.2024 03:14:39
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2017-15410
- EPSS 0.94%
- Published 28.08.2018 19:29:03
- Last modified 21.11.2024 03:14:39
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2017-15409
- EPSS 1.1%
- Published 28.08.2018 19:29:02
- Last modified 21.11.2024 03:14:39
Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2017-15408
- EPSS 1.1%
- Published 28.08.2018 19:29:01
- Last modified 21.11.2024 03:14:39
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
CVE-2017-15407
- EPSS 2.03%
- Published 28.08.2018 19:29:00
- Last modified 21.11.2024 03:14:38
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
CVE-2018-15911
- EPSS 2.7%
- Published 28.08.2018 04:29:00
- Last modified 21.11.2024 03:51:42
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
CVE-2018-15908
- EPSS 0.23%
- Published 27.08.2018 17:29:00
- Last modified 21.11.2024 03:51:41
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
CVE-2018-15909
- EPSS 2.27%
- Published 27.08.2018 17:29:00
- Last modified 21.11.2024 03:51:41
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
CVE-2018-15910
- EPSS 4.83%
- Published 27.08.2018 17:29:00
- Last modified 21.11.2024 03:51:42
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
- EPSS 5.54%
- Published 26.08.2018 16:29:00
- Last modified 21.11.2024 01:28:55
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control ...