Redhat Enterprise Linux Desktop vulnerabilities
1,928 known vulnerabilities affecting redhat/enterprise_linux_desktop.
Total CVEs
1,928
CISA KEV
56
actively exploited
Public exploits
141
Exploited in wild
61
Severity breakdown
CRITICAL345HIGH708MEDIUM756LOW119
Vulnerabilities
Page 18 of 97
CVE-2018-16066MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-16066 [MEDIUM] CWE-416 CVE-2018-16066: A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potent
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6117MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6117 [MEDIUM] CWE-200 CVE-2018-6117: Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to
Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6096MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6096 [MEDIUM] CWE-20 CVE-2018-6096: A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome
A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2018-6109MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6109 [MEDIUM] CWE-200 CVE-2018-6109: readAsText() can indefinitely read the file picked by the user, rather than only once at the time th
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
nvd
CVE-2018-6165MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6165 [MEDIUM] CVE-2018-6165: Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote
Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6137MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6137 [MEDIUM] CWE-200 CVE-2018-6137: CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cros
CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6093MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6093 [MEDIUM] CWE-200 CVE-2018-6093: Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke
Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6123MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6123 [MEDIUM] CWE-416 CVE-2018-6123: A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potent
A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6133MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6133 [MEDIUM] CWE-19 CVE-2018-6133: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-16079MEDIUMCVSS 5.3v6.02019-01-09
CVE-2018-16079 [MEDIUM] CWE-362 CVE-2018-16079: A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.
A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-16088MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-16088 [MEDIUM] CWE-20 CVE-2018-16088: A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowe
A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page.
nvd
CVE-2018-6172MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6172 [MEDIUM] CVE-2018-6172: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6173MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6173 [MEDIUM] CVE-2018-6173: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6100MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6100 [MEDIUM] CWE-19 CVE-2018-6100: Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0
Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6179MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6179 [MEDIUM] CWE-200 CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chr
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2018-6135MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6135 [MEDIUM] CVE-2018-6135: Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome pr
Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-20662MEDIUMCVSS 6.5v7.02019-01-03
CVE-2018-20662 [MEDIUM] CWE-20 CVE-2018-20662: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (applica
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
nvd
CVE-2018-16876MEDIUMCVSS 5.3v7.02019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
nvd
CVE-2018-20650MEDIUMCVSS 6.5v7.02019-01-01
CVE-2018-20650 [MEDIUM] CWE-20 CVE-2018-20650: A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of ser
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
nvd
CVE-2018-1000877HIGHCVSS 8.8v7.02018-12-20
CVE-2018-1000877 [HIGH] CWE-415 CVE-2018-1000877: libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via t
nvd