VYPR

Vendor CVEs

Red Hat

All CVEs

6,364 total · sorted by risk
  • CVE-2018-12022HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.07

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an…

  • CVE-2018-18494MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.01

    A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This…

  • CVE-2018-12396MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR <…

  • CVE-2019-5781MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5778MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome…

  • CVE-2019-5777MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5776MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5775MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5773MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.03

    Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.

  • CVE-2019-5768MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • CVE-2019-5767MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

  • CVE-2019-5766MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5754MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.

  • CVE-2019-2533MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to…

  • CVE-2018-16846MedJan 15, 2019
    risk 0.42cvss 6.5epss 0.02

    It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.

  • CVE-2018-6179MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-6175MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6173MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6172MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6169MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.

  • CVE-2018-6167MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6166MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6165MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-6164MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-6163MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6143MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-6137MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-6135MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2018-6133MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6123MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.03

    A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-6117MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2018-6114MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect enforcement of CSP for tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2018-6113MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2018-6109MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML…

  • CVE-2018-6100MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6097MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page.

  • CVE-2018-6096MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.

  • CVE-2018-6093MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-6091MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Service Workers can intercept any request made by an or tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-17459MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-16088MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page.

  • CVE-2018-16082MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2018-16078MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2018-16067MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-16066MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-20662MedJan 3, 2019
    risk 0.42cvss 6.5epss 0.02

    In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during…

  • CVE-2018-20650MedJan 1, 2019
    risk 0.42cvss 6.5epss 0.03

    A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

  • CVE-2018-20097MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-18353MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page.

  • CVE-2018-18352MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass same origin policy for audio content via a crafted HTML page.

Page 51 of 128