CVE-2018-12393
- EPSS 5.97%
- Published 28.02.2019 18:29:00
- Last modified 21.11.2024 03:45:07
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bou...
CVE-2018-12395
- EPSS 3.02%
- Published 28.02.2019 18:29:00
- Last modified 21.11.2024 03:45:08
By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Fir...
CVE-2018-12396
- EPSS 1.18%
- Published 28.02.2019 18:29:00
- Last modified 21.11.2024 03:45:08
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulner...
CVE-2018-12397
- EPSS 0.07%
- Published 28.02.2019 18:29:00
- Last modified 21.11.2024 03:45:08
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permissi...
CVE-2019-1559
- EPSS 5.05%
- Published 27.02.2019 23:29:00
- Last modified 21.11.2024 04:36:48
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid...
CVE-2019-5780
- EPSS 0.03%
- Published 19.02.2019 17:29:02
- Last modified 21.11.2024 04:45:28
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
CVE-2019-5781
- EPSS 0.85%
- Published 19.02.2019 17:29:02
- Last modified 21.11.2024 04:45:28
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2019-5782
- EPSS 79.8%
- Published 19.02.2019 17:29:02
- Last modified 21.11.2024 04:45:28
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2019-5766
- EPSS 0.88%
- Published 19.02.2019 17:29:01
- Last modified 21.11.2024 04:45:27
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-5767
- EPSS 0.49%
- Published 19.02.2019 17:29:01
- Last modified 21.11.2024 04:45:27
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.