Show filters
963 Total Results
Displaying 171-180 of 963
Sort by:
Attacker Value
Unknown
CVE-2018-6100
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
0
Attacker Value
Unknown
CVE-2018-6112
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6126
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-20662
Disclosure Date: January 03, 2019 (last updated November 08, 2023)
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
0
Attacker Value
Unknown
CVE-2018-20650
Disclosure Date: January 01, 2019 (last updated November 27, 2024)
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
0
Attacker Value
Unknown
CVE-2018-19134
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
0
Attacker Value
Unknown
CVE-2018-1000878
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
0
Attacker Value
Unknown
CVE-2018-1000877
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
0
Attacker Value
Unknown
CVE-2018-15127
Disclosure Date: December 19, 2018 (last updated November 27, 2024)
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
0
Attacker Value
Unknown
CVE-2018-20097
Disclosure Date: December 12, 2018 (last updated November 08, 2023)
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
0