Latest CVE Feed
-
7.8
HIGHCVE-2017-15404
An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privilege escalation in Crash Reporting in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to perform privilege es... Read more
Affected Products : chrome- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2017-15403
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-15402
Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had comp... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15401
A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-15400
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.... Read more
Affected Products : chrome_os- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-15399
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Aug. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15398
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Aug. 28, 2018
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2017-15397
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.... Read more
Affected Products : chrome_os- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15396
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a... Read more
- Published: Aug. 28, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15395
A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15394
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15393
Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to remote debugging functionality via a crafted HTML page, aka a Referer leak.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-15392
Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15391
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15390
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15389
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15388
Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15387
Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15386
Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15367
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.... Read more
Affected Products : bacula-web- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024