CVE-2018-18354
- EPSS 1.62%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:46
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
CVE-2018-18355
- EPSS 0.95%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:46
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2018-18356
- EPSS 2.61%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:46
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-17480
- EPSS 27.43%
- Veröffentlicht 11.12.2018 16:29:00
- Zuletzt bearbeitet 06.03.2025 19:48:51
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2018-18335
- EPSS 1.8%
- Veröffentlicht 11.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:44
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-5800
- EPSS 1.68%
- Veröffentlicht 07.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:25
An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
CVE-2018-5801
- EPSS 1.59%
- Veröffentlicht 07.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:26
An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference.
CVE-2018-5802
- EPSS 0.61%
- Veröffentlicht 07.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:26
An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.
CVE-2018-5805
- EPSS 0.56%
- Veröffentlicht 07.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:26
A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.
CVE-2018-5806
- EPSS 0.53%
- Veröffentlicht 07.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:26
An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.