CVE-2017-15390
- EPSS 0.79%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:37
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
CVE-2017-15391
- EPSS 0.79%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:37
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.
CVE-2017-15392
- EPSS 0.41%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:37
Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.
CVE-2017-15393
- EPSS 1.06%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:37
Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to remote debugging functionality via a crafted HTML page, aka a Referer leak.
CVE-2017-15394
- EPSS 1.3%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:37
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.
CVE-2017-15395
- EPSS 1.49%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:37
A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.
CVE-2017-5124
- EPSS 25%
- Veröffentlicht 07.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:27:06
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
CVE-2018-6574
- EPSS 36.79%
- Veröffentlicht 07.02.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:55
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not bloc...
CVE-2018-6794
- EPSS 37.43%
- Veröffentlicht 07.02.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:12
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server wi...
CVE-2018-6799
- EPSS 0.78%
- Veröffentlicht 07.02.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:13
The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging a...