Show filters
557 Total Results
Displaying 121-130 of 557
Sort by:
Attacker Value
Unknown
CVE-2018-0692
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2018-6065
Disclosure Date: November 14, 2018 (last updated June 29, 2024)
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-10496
Disclosure Date: September 24, 2018 (last updated November 27, 2024)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.15. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of TypedArray objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5326.
0
Attacker Value
Unknown
CVE-2018-14730
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any origin.
0
Attacker Value
Unknown
CVE-2017-16639
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-16983
Disclosure Date: September 13, 2018 (last updated November 27, 2024)
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.
0
Attacker Value
Unknown
CVE-2018-16549
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
0
Attacker Value
Unknown
CVE-2018-10895
Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2018-1000559
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the victim must open a page with a specially crafted <title> attribute, and then open the qute://history site via the :history command. This vulnerability appears to have been fixed in fixed in v1.3.3 (4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0 (5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week).
0
Attacker Value
Unknown
MFSBGN03809 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF
Disclosure Date: June 16, 2018 (last updated November 08, 2023)
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
0