|
246271
|
6.1 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
The default selected dialog button in CustomHandlers in Google Chrome prior to 69.0.3497.81 allowed a remote attacker who convinced the user to perform certain operations to open external programs vi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16084
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246272
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16083
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246273
|
6.5 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16082
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246274
|
7.4 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on…
|
CWE-862
Missing Authorization
|
CVE-2018-16081
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246275
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML pag…
|
CWE-20
Improper Input Validation
|
CVE-2018-16080
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246276
|
5.3 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HT…
|
CWE-362
Race Condition
|
CVE-2018-16079
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246277
|
6.5 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML …
|
CWE-200
Information Exposure
|
CVE-2018-16078
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246278
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16076
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246279
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
|
CWE-346
Origin Validation Error
|
CVE-2018-16072
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246280
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-16071
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|