CVE-2018-4262 – Apple Safari RegExp Exec Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-4262
By performing actions in JavaScript, an attacker can trigger a type confusion condition. • http://www.securitytracker.com/id/1041232 https://security.gentoo.org/glsa/201808-04 https://support.apple.com/HT208934%2C https://support.apple.com/HT208935 https://support.apple.com/HT208938%2C https://usn.ubuntu.com/3743-1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-6149 – chromium-browser: Out of bounds write in V8
https://notcve.org/view.php?id=CVE-2018-6149
Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. La confusión de tipos en JavaScript en Google Chrome antes de 67.0.3396.87 permitió a un atacante remoto realizar una escritura de memoria fuera de límites a través de una página HTML diseñada. • https://chromereleases.googleblog.com/2018/06/stable-channel-update-for-desktop_12.html https://crbug.com/848672 https://access.redhat.com/security/cve/CVE-2018-6149 https://bugzilla.redhat.com/show_bug.cgi?id=1590681 • CWE-787: Out-of-bounds Write •
CVE-2018-12453 – Redis 5.0 - Denial of Service
https://notcve.org/view.php?id=CVE-2018-12453
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream. Confusión de tipos en la función xgroupCommand en t_stream.c en redis-server en Redis en versiones anteriores a la 5.0 permite que atacantes remotos provoquen una denegación de servicio (DoS) mediante un comando XGROUP en el que la clave no es una secuencia. • https://www.exploit-db.com/exploits/44908 https://gist.github.com/fakhrizulkifli/34a56d575030682f6c564553c53b82b5 https://github.com/antirez/redis/commit/c04082cf138f1f51cedf05ee9ad36fb6763cafc6 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2018-8229 – Microsoft Edge Chakra JIT - Type Confusion with Hoisted SetConcatStrMultiItemBE Instructions
https://notcve.org/view.php?id=CVE-2018-8229
Microsoft Edge Chakra JIT suffers from a type confusion vulnerability with hoisted SetConcatStrMultiItemBE instructions. • https://www.exploit-db.com/exploits/45013 http://www.securityfocus.com/bid/104369 http://www.securitytracker.com/id/1041097 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8229 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2018-6124 – chromium-browser: Type confusion in Blink
https://notcve.org/view.php?id=CVE-2018-6124
Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. Confusión de tipos en ReadableStreams en Blink en Google Chrome, en versiones anteriores a la 67.0.3396.62, permitía que un atacante remoto pudiese explotar una corrupción de objetos mediante una página HTML manipulada. • http://www.securityfocus.com/bid/104309 http://www.securitytracker.com/id/1041014 https://access.redhat.com/errata/RHSA-2018:1815 https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html https://crbug.com/840320 https://www.debian.org/security/2018/dsa-4237 https://access.redhat.com/security/cve/CVE-2018-6124 https://bugzilla.redhat.com/show_bug.cgi?id=1584033 • CWE-704: Incorrect Type Conversion or Cast •