CVE-2018-6074
- EPSS 0.55%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:00
Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.
CVE-2018-6075
- EPSS 0.73%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:00
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
CVE-2018-6076
- EPSS 0.49%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:00
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
CVE-2018-6077
- EPSS 0.73%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:00
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-6078
- EPSS 0.66%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:01
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2018-6079
- EPSS 0.67%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:01
Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-6080
- EPSS 0.75%
- Veröffentlicht 14.11.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:01
Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .
CVE-2018-17462
- EPSS 1.31%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:28
Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML page.
CVE-2018-17463
- EPSS 92.2%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 24.10.2025 14:11:07
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2018-17464
- EPSS 0.91%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:28
Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.