Redhat

Enterprise Linux Server

1891 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 28.02.2019 18:29:00
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permissi...

  • EPSS 5.05%
  • Veröffentlicht 27.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:36:48

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid...

  • EPSS 0.03%
  • Veröffentlicht 19.02.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:45:28

Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.

  • EPSS 0.84%
  • Veröffentlicht 19.02.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:45:28

Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • EPSS 79.61%
  • Veröffentlicht 19.02.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:45:28

Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • EPSS 0.86%
  • Veröffentlicht 19.02.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:45:27

Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • EPSS 0.48%
  • Veröffentlicht 19.02.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:45:27

Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

  • EPSS 0.48%
  • Veröffentlicht 19.02.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:45:27

DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • EPSS 1.62%
  • Veröffentlicht 19.02.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:45:27

Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 1.11%
  • Veröffentlicht 19.02.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:45:27

Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.