Show filters
964 Total Results
Displaying 271-280 of 964
Sort by:
Attacker Value
Unknown
CVE-2018-6050
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6047
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6042
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6048
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6037
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6046
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
0
Attacker Value
Unknown
CVE-2018-6038
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-6052
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.
0
Attacker Value
Unknown
CVE-2018-6033
Disclosure Date: September 25, 2018 (last updated November 08, 2023)
Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted Chrome Extension.
0
Attacker Value
Unknown
CVE-2018-14633
Disclosure Date: September 25, 2018 (last updated November 27, 2024)
A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. Kernel versions 4.18.x, 4.14.x and 3.10.x are believed to be vulnerable.
0