|
246591
|
7.5 |
HIGH
Network
|
swift
|
alliance_web_platform
|
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.e…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2018-16386
|
2024-11-21 12:52 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246592
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions vi…
|
CWE-285
Improper Authorization
|
CVE-2018-16086
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246593
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML page.
|
CWE-285
Improper Authorization
|
CVE-2018-16077
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246594
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain local file data via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-16075
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246595
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
|
CWE-285
Improper Authorization
|
CVE-2018-16074
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246596
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
|
CWE-285
Improper Authorization
|
CVE-2018-16073
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246597
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-16070
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246598
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16069
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246599
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a…
|
CWE-20
Improper Input Validation
|
CVE-2018-16064
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246600
|
8.1 |
HIGH
Network
|
sophos
|
sfos
|
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metac…
|
CWE-78
OS Command
|
CVE-2018-16118
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|