Show filters
963 Total Results
Displaying 161-170 of 963
Sort by:
Attacker Value
Unknown
CVE-2018-16864
Disclosure Date: January 11, 2019 (last updated November 27, 2024)
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
0
Attacker Value
Unknown
CVE-2019-6133
Disclosure Date: January 11, 2019 (last updated November 27, 2024)
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
0
Attacker Value
Unknown
CVE-2018-6091
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6097
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6096
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6093
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6110
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.
0
Attacker Value
Unknown
CVE-2018-6109
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6106
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote attacker to potentially exploit object corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6056
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
0