VYPR

Vendor CVEs

Red Hat

All CVEs

6,364 total · sorted by risk
  • CVE-2018-18351MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.03

    Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.

  • CVE-2018-18350MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2018-18349MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-18346MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page.

  • CVE-2018-18345MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer process to bypass site isolation protections via a crafted HTML page.

  • CVE-2018-18344MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-6116MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2018-6108MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.

  • CVE-2018-6107MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6105MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6104MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6103MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.

  • CVE-2018-6099MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

  • CVE-2018-6098MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2018-6095MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.

  • CVE-2018-6089MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

  • CVE-2018-16476HigNov 30, 2018
    risk 0.42cvss 7.5epss 0.02

    A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions…

  • CVE-2018-6080MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .

  • CVE-2018-6079MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-6077MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-6075MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.

  • CVE-2018-6069MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-6066MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.04

    Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-17468MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obtain cross origin URLs via a crafted HTML page.

  • CVE-2018-19208MedNov 12, 2018
    risk 0.42cvss 6.5epss 0.01

    In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

  • CVE-2018-19058MedNov 7, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file.

  • CVE-2018-18897MedNov 2, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.

  • CVE-2018-14660MedNov 1, 2018
    risk 0.42cvss 6.5epss 0.03

    A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory…

  • CVE-2018-14661MedOct 31, 2018
    risk 0.42cvss 6.5epss 0.03

    It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.

  • CVE-2018-14659MedOct 31, 2018
    risk 0.42cvss 6.5epss 0.02

    The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger…

  • CVE-2018-14654MedOct 31, 2018
    risk 0.42cvss 6.5epss 0.03

    The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.

  • CVE-2018-14652MedOct 31, 2018
    risk 0.42cvss 6.5epss 0.03

    The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted…

  • CVE-2018-18520MedOct 19, 2018
    risk 0.42cvss 6.5epss 0.03

    An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows…

  • CVE-2018-12373MedOct 18, 2018
    risk 0.42cvss 6.5epss 0.02

    dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

  • CVE-2018-12372MedOct 18, 2018
    risk 0.42cvss 6.5epss 0.02

    Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

  • CVE-2018-18074HigOct 9, 2018
    risk 0.42cvss 7.5epss 0.07

    The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

  • CVE-2018-17581MedSep 28, 2018
    risk 0.42cvss 6.5epss 0.02

    CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.

  • CVE-2018-11763MedSep 25, 2018
    risk 0.42cvss 5.9epss 0.45

    In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2…

  • CVE-2018-6050MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2018-6049MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.

  • CVE-2018-6045MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.

  • CVE-2018-6040MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security policy via a crafted HTML page.

  • CVE-2018-6038MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-6037MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.

  • CVE-2018-6036MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user data via a crafted HTML page.

  • CVE-2018-6032MedSep 25, 2018
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted HTML page.

  • CVE-2018-1114MedSep 11, 2018
    risk 0.42cvss 6.5epss 0.02

    It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

  • CVE-2018-10935MedSep 11, 2018
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

  • CVE-2018-10930MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.

  • CVE-2018-10914MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.02

    It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

Page 52 of 128