VYPR

Enterprise Linux Desktop

by Red Hat

CVEs (1,928)

  • CVE-2018-6078MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2018-17477MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.

  • CVE-2018-17476MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.

  • CVE-2018-17475MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-17471MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.

  • CVE-2018-17467MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-12374MedOct 18, 2018
    risk 0.28cvss 4.3epss 0.02

    Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.

  • CVE-2018-6052MedSep 25, 2018
    risk 0.28cvss 4.3epss 0.01

    Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.

  • CVE-2018-6051MedSep 25, 2018
    risk 0.28cvss 4.3epss 0.01

    XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.

  • CVE-2018-6048MedSep 25, 2018
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.

  • CVE-2018-6047MedSep 25, 2018
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.

  • CVE-2018-6042MedSep 25, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-6041MedSep 25, 2018
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2017-15418MedAug 28, 2018
    risk 0.28cvss 4.3epss 0.02

    Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2017-12173MedJul 27, 2018
    risk 0.28cvss 4.3epss 0.01

    It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated…

  • CVE-2018-2940MedJul 18, 2018
    risk 0.28cvss 4.3epss 0.03

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2018-5170MedJun 11, 2018
    risk 0.28cvss 4.3epss 0.02

    It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2018-5161MedJun 11, 2018
    risk 0.28cvss 4.3epss 0.02

    Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2017-7847MedJun 11, 2018
    risk 0.28cvss 4.3epss 0.02

    Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.

  • CVE-2017-5451MedJun 11, 2018
    risk 0.28cvss 4.3epss 0.02

    A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This…

Page 65 of 97