|
253431
|
8.8 |
HIGH
Network
|
redhat debian google xmlsoft
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux chrome libxml2
|
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2017-15412
|
2024-11-21 12:14 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253432
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2017-15411
|
2024-11-21 12:14 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253433
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2017-15410
|
2024-11-21 12:14 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253434
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15409
|
2024-11-21 12:14 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253435
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15408
|
2024-11-21 12:14 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253436
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15407
|
2024-11-21 12:14 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253437
|
7.5 |
HIGH
Network
|
openstack redhat
|
cinder openstack
|
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically af…
|
CWE-200
Information Exposure
|
CVE-2017-15139
|
2024-11-21 12:14 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253438
|
5.0 |
MEDIUM
Network
|
redhat
|
openshift_container_platform
|
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
|
CWE-200
Information Exposure
|
CVE-2017-15138
|
2024-11-21 12:14 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253439
|
7.0 |
HIGH
Local
|
charlesproxy
|
charles
|
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.
|
CWE-362
Race Condition
|
CVE-2017-15358
|
2024-11-21 12:14 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253440
|
9.8 |
CRITICAL
Network
|
qemu redhat canonical
|
qemu enterprise_linux ubuntu_linux
|
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be li…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15118
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|