CVE-2018-6054
- EPSS 1.44%
- Veröffentlicht 25.09.2018 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:09:58
Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
CVE-2018-6055
- EPSS 0.56%
- Veröffentlicht 25.09.2018 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:09:58
Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted HTML page.
CVE-2018-6119
- EPSS 0.28%
- Veröffentlicht 25.09.2018 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:10:06
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2018-6049
- EPSS 0.69%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:57
Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.
CVE-2018-6050
- EPSS 0.91%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:57
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2018-6051
- EPSS 0.57%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:57
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
CVE-2018-6052
- EPSS 0.84%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:58
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.
CVE-2018-6053
- EPSS 0.17%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:58
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
CVE-2018-6042
- EPSS 0.91%
- Veröffentlicht 25.09.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 04:09:56
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2018-6043
- EPSS 1.56%
- Veröffentlicht 25.09.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 04:09:57
Insufficient data validation in External Protocol Handler in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially execute arbitrary programs on user machine via a crafted HTML page.