CVE-2018-16065
- EPSS 2.54%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:01
A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2018-16066
- EPSS 1.5%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-16067
- EPSS 1.38%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-16068
- EPSS 1.66%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2018-16071
- EPSS 19.89%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
CVE-2018-16076
- EPSS 0.61%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:03
Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
CVE-2016-9651
- EPSS 53.95%
- Veröffentlicht 09.01.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:34
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2018-16885
- EPSS 0.1%
- Veröffentlicht 03.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:31
A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault...
CVE-2018-16876
- EPSS 1.03%
- Veröffentlicht 03.01.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:30
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
CVE-2018-20662
- EPSS 0.46%
- Veröffentlicht 03.01.2019 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:57
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is m...