Show filters
557 Total Results
Displaying 121-130 of 557
Sort by:
Attacker Value
Unknown

CVE-2018-0692

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2018-6065

Disclosure Date: November 14, 2018 (last updated June 29, 2024)
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2018-10496

Disclosure Date: September 24, 2018 (last updated November 27, 2024)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.15. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of TypedArray objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5326.
0
Attacker Value
Unknown

CVE-2018-14730

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any origin.
Attacker Value
Unknown

CVE-2017-16639

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2018-16983

Disclosure Date: September 13, 2018 (last updated November 27, 2024)
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.
0
Attacker Value
Unknown

CVE-2018-16549

Disclosure Date: September 05, 2018 (last updated November 27, 2024)
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
0
Attacker Value
Unknown

CVE-2018-10895

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.
0
Attacker Value
Unknown

CVE-2018-1000559

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the victim must open a page with a specially crafted <title> attribute, and then open the qute://history site via the :history command. This vulnerability appears to have been fixed in fixed in v1.3.3 (4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0 (5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week).
0
Attacker Value
Unknown

MFSBGN03809 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF

Disclosure Date: June 16, 2018 (last updated November 08, 2023)
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).