|
246511
|
4.8 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vu…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17256
|
2024-11-21 12:54 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246512
|
9.8 |
CRITICAL
Network
|
apache
|
spark
|
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute…
|
NVD-CWE-noinfo
|
CVE-2018-17190
|
2024-11-21 12:54 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246513
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17477
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246514
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17476
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246515
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17475
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246516
|
8.8 |
HIGH
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-17474
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246517
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome linux_desktop linux_workstation linux_server debian_linux
|
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
|
NVD-CWE-noinfo
|
CVE-2018-17473
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246518
|
9.6 |
CRITICAL
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <iframe> sandbox via a crafted HTML page.
|
CWE-20
Improper Input Validation
|
CVE-2018-17472
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246519
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17471
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246520
|
8.8 |
HIGH
Network
|
google redhat debian
|
chrome linux_desktop linux_workstation linux_server debian_linux
|
Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17469
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|