CVE-2018-17470
- EPSS 1.51%
- Veröffentlicht 09.01.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 03:54:29
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2018-16065
- EPSS 2.4%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:01
A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2018-16066
- EPSS 1.41%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-16067
- EPSS 1.3%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-16068
- EPSS 1.56%
- Veröffentlicht 09.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:02
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2019-5716
- EPSS 0.27%
- Veröffentlicht 08.01.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:22
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
CVE-2019-5717
- EPSS 0.27%
- Veröffentlicht 08.01.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:23
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.
CVE-2019-5718
- EPSS 0.27%
- Veröffentlicht 08.01.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:23
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.
CVE-2019-5719
- EPSS 0.13%
- Veröffentlicht 08.01.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:23
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block.
CVE-2018-1320
- EPSS 0.09%
- Veröffentlicht 07.01.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:37
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed co...