cbcvebase.

Redhat Linux Desktop vulnerabilities

44 known vulnerabilities affecting redhat/linux_desktop.

Total CVEs
44
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM20

Vulnerabilities

Page 2 of 3
CVE-2018-18359P3HIGHCVSS 8.8v6.02018-12-11
CVE-2018-18359 [HIGH] CWE-125 CVE-2018-18359: Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remot Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6072P3HIGHCVSS 8.8v6.02018-11-14
CVE-2018-6072 [HIGH] CWE-190 CVE-2018-6072: An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allo An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-17469P3HIGHCVSS 8.8v6.02018-11-14
CVE-2018-17469 [HIGH] CWE-125 CVE-2018-17469: Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a r Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2018-6071P3HIGHCVSS 8.8v6.02018-11-14
CVE-2018-6071 [HIGH] CWE-125 CVE-2018-6071: An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to per An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6069P4MEDIUMCVSS 6.5v6.02018-11-14
CVE-2018-6069 [MEDIUM] CWE-125 CVE-2018-6069: Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to p Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6066P4MEDIUMCVSS 6.5v6.02018-11-14
CVE-2018-6066 [MEDIUM] CWE-200 CVE-2018-6066: Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325 Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6095P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6095 [MEDIUM] CWE-200 CVE-2018-6095: Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.33 Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
nvd
CVE-2018-6099P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6099 [MEDIUM] CWE-200 CVE-2018-6099: A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
nvd
CVE-2018-6089P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6089 [MEDIUM] CWE-20 CVE-2018-6089: A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
nvd
CVE-2018-6103P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6103 [MEDIUM] CVE-2018-6103: A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote att A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.
nvd
CVE-2018-6098P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6098 [MEDIUM] CVE-2018-6098: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6104P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6104 [MEDIUM] CVE-2018-6104: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6107P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6107 [MEDIUM] CVE-2018-6107: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6105P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6105 [MEDIUM] CVE-2018-6105: Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allow Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6075P4MEDIUMCVSS 6.5v6.02018-11-14
CVE-2018-6075 [MEDIUM] CWE-200 CVE-2018-6075: Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
nvd
CVE-2018-6116P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6116 [MEDIUM] CWE-476 CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attack A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-18346P4MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18346 [MEDIUM] CVE-2018-18346: Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a re Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page.
nvd
CVE-2018-6108P4MEDIUMCVSS 6.5v6.02018-12-04
CVE-2018-6108 [MEDIUM] CVE-2018-6108: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.
nvd
CVE-2018-6076P4MEDIUMCVSS 6.1v6.02018-11-14
CVE-2018-6076 [MEDIUM] CWE-79 CVE-2018-6076: Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 a Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
nvd
CVE-2018-6081P4MEDIUMCVSS 6.1v6.02018-11-14
CVE-2018-6081 [MEDIUM] CWE-79 CVE-2018-6081: XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
nvd
Redhat Linux Desktop vulnerabilities | cvebase