Show filters
997 Total Results
Displaying 161-170 of 997
Sort by:
Attacker Value
Unknown
CVE-2018-6109
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6106
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote attacker to potentially exploit object corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6056
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6100
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
0
Attacker Value
Unknown
CVE-2018-6112
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6126
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-20662
Disclosure Date: January 03, 2019 (last updated November 08, 2023)
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
0
Attacker Value
Unknown
CVE-2018-20650
Disclosure Date: January 01, 2019 (last updated November 27, 2024)
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
0
Attacker Value
Unknown
CVE-2018-19134
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
0
Attacker Value
Unknown
CVE-2018-1000878
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
0