CVE-2018-6170 – chromium-browser: Type confusion in PDFium
https://notcve.org/view.php?id=CVE-2018-6170
A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Una mala conversión en PDFium en Google Chrome, en versiones anteriores a la 68.0.3440.75, permitía que un atacante remoto pudiese explotar una corrupción de memoria dinámica (heap) mediante un archivo PDF manipulado. • http://www.securityfocus.com/bid/104887 https://access.redhat.com/errata/RHSA-2018:2282 https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html https://crbug.com/862059 https://security.gentoo.org/glsa/201808-01 https://www.debian.org/security/2018/dsa-4256 https://access.redhat.com/security/cve/CVE-2018-6170 https://bugzilla.redhat.com/show_bug.cgi?id=1608194 • CWE-704: Incorrect Type Conversion or Cast CWE-787: Out-of-bounds Write •
CVE-2018-6157 – chromium-browser: Type confusion in WebRTC
https://notcve.org/view.php?id=CVE-2018-6157
Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. La confusión de tipos en WebRTC en Google Chrome antes de 68.0.3440.75 permitió a un atacante remoto explotar potencialmente la corrupción del montón a través de un archivo de video creado. • https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html https://crbug.com/840536 https://access.redhat.com/security/cve/CVE-2018-6157 https://bugzilla.redhat.com/show_bug.cgi?id=1608181 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2018-12812
https://notcve.org/view.php?id=CVE-2018-12812
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusion vulnerability. ... Adobe Acrobat y Reader 2018.011.20038 y anteriores, 2017.011.30079 y anteriores y 2015.006.30417 y anteriores, tienen una vulnerabilidad de confusión de tipos. • https://helpx.adobe.com/security/products/acrobat/apsb18-09.html • CWE-704: Incorrect Type Conversion or Cast •
CVE-2018-11623 – Foxit Reader addAdLayer Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-11623
By performing actions in JavaScript, an attacker can trigger a type confusion condition. ... Realizando acciones en JavaScript, un atacante puede desencadenar una condición de confusión de tipos. ... By performing actions in JavaScript, an attacker can trigger a type confusion condition. • https://www.foxitsoftware.com/support/security-bulletins.php https://zerodayinitiative.com/advisories/ZDI-18-700 • CWE-704: Incorrect Type Conversion or Cast CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2018-14241 – Foxit Reader addAnnot Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-14241
By performing actions in JavaScript, an attacker can trigger a type confusion condition. ... Realizando acciones en JavaScript, un atacante puede desencadenar una condición de confusión de tipos. ... By performing actions in JavaScript, an attacker can trigger a type confusion condition. • https://www.foxitsoftware.com/support/security-bulletins.php https://zerodayinitiative.com/advisories/ZDI-18-701 • CWE-704: Incorrect Type Conversion or Cast CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •