CVE-2018-6116NULL Pointer Dereference in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
1.5%
top 18.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 4
Latest updateMay 14

Description

A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5google/chromeunspecified66.0.3359.117
NVDgoogle/chrome< 66.0.3359.117

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-5h45-8j9q-c6wv: A nullptr dereference in WebAssembly in Google Chrome prior to 662022-05-14
CVEList
CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 662018-12-04
OSV
CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 662018-12-04

📋Vendor Advisories

1
Red Hat
chromium-browser: Incorrect low memory handling in WebAssembly2018-04-17

💬Community

3
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-61162019-02-07
Bugzilla
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)2019-01-16
Bugzilla
CVE-2018-6116 chromium-browser: Incorrect low memory handling in WebAssembly2018-04-18