- EPSS 0.01%
- Veröffentlicht 09.01.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:38
Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.31...
CVE-2018-20346
- EPSS 13.22%
- Veröffentlicht 21.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:17
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by l...
CVE-2018-18357
- EPSS 0.91%
- Veröffentlicht 11.12.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:47
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2018-18358
- EPSS 0.11%
- Veröffentlicht 11.12.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:47
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
CVE-2018-18359
- EPSS 1.16%
- Veröffentlicht 11.12.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:47
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2018-18340
- EPSS 1.56%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:44
Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-18341
- EPSS 1.67%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:44
An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-18342
- EPSS 1.89%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:45
Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra...
CVE-2018-18343
- EPSS 1.56%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:45
Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-18344
- EPSS 0.96%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:45
Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted ...