CVE-2018-17476
- EPSS 0.91%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:30
Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
CVE-2018-17477
- EPSS 0.77%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:30
Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.
CVE-2018-6057
- EPSS 0.53%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:58
Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.
CVE-2018-16471
- EPSS 0.17%
- Veröffentlicht 13.11.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:49
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do no...
CVE-2018-19210
- EPSS 4.91%
- Veröffentlicht 12.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:33
In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.
CVE-2018-19216
- EPSS 0.23%
- Veröffentlicht 12.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:34
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
CVE-2018-19206
- EPSS 2.36%
- Veröffentlicht 12.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:33
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
CVE-2018-19198
- EPSS 0.68%
- Veröffentlicht 12.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:32
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
CVE-2018-19199
- EPSS 0.7%
- Veröffentlicht 12.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:32
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
CVE-2018-19200
- EPSS 1.12%
- Veröffentlicht 12.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:32
An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.