CVE-2018-6053
published 2018-09-25CVE-2018-6053: Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing…
PriorityP49low3.3CVSS 3.0
AVLACLPRNUIRSUCLINAN
EPSS
0.76%
51.5th percentile
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| david_king | vino | >= 0 < 3.8.1-0ubuntu9.3 | 3.8.1-0ubuntu9.3 |
| david_king | vino | >= 0 < 3.22.0-3ubuntu1.1 | 3.22.0-3ubuntu1.1 |
| david_king | vino | >= 0 < 3.22.0-5ubuntu2.1 | 3.22.0-5ubuntu2.1 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 64.0.3282.119 | 64.0.3282.119 | |
| chrome | >= unspecified < 64.0.3282.119 | 64.0.3282.119 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: leak of page thumbnails in new tab page
vendor_redhat·2018-01-24·CVSS 3.3
CVE-2018-6053 [LOW] chromium-browser: leak of page thumbnails in new tab page
chromium-browser: leak of page thumbnails in new tab page
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
GHSA
GHSA-c5vp-q9xm-7xrq: Inappropriate implementation in New Tab Page in Google Chrome prior to 64
ghsa_unreviewed·2022-05-14
CVE-2018-6053 [MEDIUM] CWE-200 GHSA-c5vp-q9xm-7xrq: Inappropriate implementation in New Tab Page in Google Chrome prior to 64
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
OSV
vino vulnerabilities
osv·2020-10-07·CVSS 5.0
CVE-2014-6053 vino vulnerabilities
vino vulnerabilities
Nicolas Ruff discovered that Vino incorrectly handled large ClientCutText
messages. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. (CVE-2014-6053)
It was discovered that Vino incorrectly handled certain packet lengths. A
remote attacker could possibly use this issue to obtain sensitive
information, cause a denial of service, or execute arbitrary code.
(CVE-2018-7225)
Pavel Cheremushkin discovered that an information disclosure vulnerability
existed in Vino when sending a ServerCutText message. An attacker could
possibly use this issue to expose sensitive information. (CVE-2019-15681)
It was discovered that Vino incorrectly handled region clipping. A remote
attacker could possibly use this issue to cause Vino t
OSV
CVE-2018-6053: Inappropriate implementation in New Tab Page in Google Chrome prior to 64
osv·2018-09-25·CVSS 3.3
CVE-2018-6053 [LOW] CVE-2018-6053: Inappropriate implementation in New Tab Page in Google Chrome prior to 64
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102797http://www.securitytracker.com/id/1040282https://access.redhat.com/errata/RHSA-2018:0265https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/758169https://www.debian.org/security/2018/dsa-4103http://www.securityfocus.com/bid/102797http://www.securitytracker.com/id/1040282https://access.redhat.com/errata/RHSA-2018:0265https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/758169https://www.debian.org/security/2018/dsa-4103
2018-09-25
Published