CVE-2018-6151 – chromium-browser: Bad cast in DevTools
https://notcve.org/view.php?id=CVE-2018-6151
27 Jul 2018 — Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. Una mala conversión en DevTools en Google Chrome, en versiones anteriores a la 66.0.3359.117 para Windows, Linux, Mac y Chrome OS, permitía que un atacante, que hubiese convencido a un usuario para que instale una extensión maliciosa, realizase una lectura de memoria fuera d... • http://www.securityfocus.com/bid/104887 • CWE-125: Out-of-bounds Read •
CVE-2018-6152 – chromium-browser: Local file write in DevTools
https://notcve.org/view.php?id=CVE-2018-6152
27 Jul 2018 — The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction. La implementación del backend Page.downloadBehavior marcaba incondicionalmente los archivos descargados como seguros, independientemente del tipo de archivo en Google Chrome, en versi... • http://www.securityfocus.com/bid/104887 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2018-6153 – chromium-browser: Stack buffer overflow in Skia
https://notcve.org/view.php?id=CVE-2018-6153
27 Jul 2018 — A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. Un error de precisión en Skia en Google Chrome, en versiones anteriores a la 68.0.3440.75, permitía que un atacante remoto que hubiese comprometido el proceso renderer pudiese realizar una escritura de memoria fuera de límites mediante una página HTML manipulada. Chromium is an open-source web browser, powered by... • http://www.securityfocus.com/bid/104887 • CWE-787: Out-of-bounds Write •
CVE-2018-6149 – chromium-browser: Out of bounds write in V8
https://notcve.org/view.php?id=CVE-2018-6149
19 Jun 2018 — Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. La confusión de tipos en JavaScript en Google Chrome antes de 67.0.3396.87 permitió a un atacante remoto realizar una escritura de memoria fuera de límites a través de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 67.0.3396.87. Issues addressed include an out of bounds wr... • https://chromereleases.googleblog.com/2018/06/stable-channel-update-for-desktop_12.html • CWE-787: Out-of-bounds Write •
CVE-2018-6148 – chromium-browser: Incorrect handling of CSP header
https://notcve.org/view.php?id=CVE-2018-6148
11 Jun 2018 — Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. La implementación incorrecta en la Política de seguridad de contenido en Google Chrome antes de 67.0.3396.79 permitió a un atacante remoto omitir las restricciones de navegación a través de una página HTML diseñada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 67.0.3396.79. Issues... • https://chromereleases.googleblog.com/2018/06/stable-channel-update-for-desktop.html • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') •
CVE-2018-6123 – chromium-browser: Use after free in Blink
https://notcve.org/view.php?id=CVE-2018-6123
07 Jun 2018 — A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de memoria previamente liberada en Blink en Google Chrome, en versiones anteriores a la 67.0.3396.62, permitía que un atacante remoto pudiese explotar una corrupción de memoria dinámica (heap) mediante una página HTML manipulada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 67.0.3396.62. Issues... • http://www.securityfocus.com/bid/104309 • CWE-416: Use After Free CWE-787: Out-of-bounds Write •
CVE-2018-6124 – chromium-browser: Type confusion in Blink
https://notcve.org/view.php?id=CVE-2018-6124
07 Jun 2018 — Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. Confusión de tipos en ReadableStreams en Blink en Google Chrome, en versiones anteriores a la 67.0.3396.62, permitía que un atacante remoto pudiese explotar una corrupción de objetos mediante una página HTML manipulada. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 67.0.3396.62. Issu... • http://www.securityfocus.com/bid/104309 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2018-6125 – chromium-browser: Overly permissive policy in WebUSB
https://notcve.org/view.php?id=CVE-2018-6125
07 Jun 2018 — Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. Una aplicación insuficiente de políticas en USB en Google Chrome en Windows versiones anteriores a 67.0.3396.62, permitía a un atacante remoto obtener información potencialmente confidencial por medio de una página HTML diseñada Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version... • https://crbug.com/818592 •
CVE-2018-6126 – Skia - Heap Overflow in SkScan::FillPath due to Precision Error
https://notcve.org/view.php?id=CVE-2018-6126
07 Jun 2018 — A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. Un error de precisión en Skia en Google Chrome, en versiones anteriores a la 67.0.3396.62, permitía que un atacante remoto pudiese realizar una escritura de memoria fuera de límites mediante una página HTML manipulada. Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Fir... • https://packetstorm.news/files/id/148684 • CWE-787: Out-of-bounds Write •
CVE-2018-6127 – chromium-browser: Use after free in indexedDB
https://notcve.org/view.php?id=CVE-2018-6127
07 Jun 2018 — Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. La liberación temprana del objeto en uso en IndexDB en Google Chrome, en versiones anteriores a la 67.0.3396.62, permitía que un atacante remoto, que hubiese comprometido el proceso renderer, pudiese realizar una escritura de memoria fuera de límites mediante una página HTML manipulada. Chromium is an... • http://www.securityfocus.com/bid/104309 • CWE-416: Use After Free •