VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2018-6113MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2018-6109MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML…

  • CVE-2018-6100MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6097MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page.

  • CVE-2018-6096MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.

  • CVE-2018-6093MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-6091MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Service Workers can intercept any request made by an or tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-16067MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-16066MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-1320HigJan 7, 2019
    risk 0.42cvss 7.5epss 0.08

    Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production…

  • CVE-2018-20662MedJan 3, 2019
    risk 0.42cvss 6.5epss 0.02

    In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during…

  • CVE-2018-20650MedJan 1, 2019
    risk 0.42cvss 6.5epss 0.03

    A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

  • CVE-2018-20622MedDec 31, 2018
    risk 0.42cvss 6.5epss 0.03

    JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.

  • CVE-2018-20584MedDec 30, 2018
    risk 0.42cvss 6.5epss 0.03

    JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.

  • CVE-2018-20570MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.02

    jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

  • CVE-2018-20544MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.02

    There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.

  • CVE-2018-20431MedDec 24, 2018
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

  • CVE-2018-20430MedDec 24, 2018
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.

  • CVE-2018-20024HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.

  • CVE-2018-20023HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used…

  • CVE-2018-20022HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it…

  • CVE-2018-20021HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.04

    LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

  • CVE-2018-20189MedDec 17, 2018
    risk 0.42cvss 6.5epss 0.02

    In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore…

  • CVE-2018-20184MedDec 17, 2018
    risk 0.42cvss 6.5epss 0.02

    In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension…

  • CVE-2018-20151HigDec 14, 2018
    risk 0.42cvss 7.5epss 0.06

    In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by…

  • CVE-2018-20097MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-18353MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page.

  • CVE-2018-18352MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass same origin policy for audio content via a crafted HTML page.

  • CVE-2018-18351MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.03

    Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.

  • CVE-2018-18350MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2018-18349MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-18346MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page.

  • CVE-2018-18345MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer process to bypass site isolation protections via a crafted HTML page.

  • CVE-2018-18344MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-19967MedDec 8, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.

  • CVE-2018-6116MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2018-6108MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.

  • CVE-2018-6107MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6105MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6104MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6103MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.

  • CVE-2018-6099MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

  • CVE-2018-6098MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6095MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.

  • CVE-2018-6089MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

  • CVE-2018-19758MedNov 30, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

  • CVE-2018-19661MedNov 29, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.

  • CVE-2018-19542MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

  • CVE-2018-19539MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.

  • CVE-2018-19432MedNov 22, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.

Page 101 of 210