|
246491
|
7.4 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-17470
|
2024-11-21 12:54 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246492
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An out of bounds read in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17461
|
2024-11-21 12:54 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246493
|
6.5 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17459
|
2024-11-21 12:54 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246494
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-17458
|
2024-11-21 12:54 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246495
|
8.8 |
HIGH
Network
|
google
|
chrome
|
An object lifecycle issue in Blink could lead to a use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…
|
CWE-416
Use After Free
|
CVE-2018-17457
|
2024-11-21 12:54 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246496
|
9.8 |
CRITICAL
Network
|
xerox
|
altalink_c8030_firmware altalink_c8035_firmware altalink_c8045_firmware altalink_c8055_firmware altalink_c8070_firmware altalink_b8045_firmware altalink_b8055_firmware altalink_b…
|
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthentic…
|
CWE-77
Command Injection
|
CVE-2018-17172
|
2024-11-21 12:54 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246497
|
7.2 |
HIGH
Network
|
apache
|
couchdb
|
Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the und…
|
NVD-CWE-noinfo
|
CVE-2018-17188
|
2024-11-21 12:54 |
2019-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246498
|
9.8 |
CRITICAL
Network
|
apache
|
netbeans
|
Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the nashorn script engine the environment of the javasc…
|
NVD-CWE-noinfo
|
CVE-2018-17191
|
2024-11-21 12:54 |
2018-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246499
|
7.5 |
HIGH
Network
|
f5 ipinfusion
|
big-ip_local_traffic_manager ocnos zebos
|
The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path con…
|
NVD-CWE-noinfo
|
CVE-2018-17539
|
2024-11-21 12:54 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246500
|
6.5 |
MEDIUM
Network
|
apache
|
tika
|
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-17197
|
2024-11-21 12:54 |
2018-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|