
CVE-2018-6122 – chromium-browser: Type confusion in V8
https://notcve.org/view.php?id=CVE-2018-6122
15 May 2018 — Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Una confusión de tipo en WebAssembly en Google Chrome versiones anteriores a 66.0.3359.139, permitía a un atacante remoto explotar potencialmente la corrupción de la pila por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in privilege escalation. Versions less ... • https://crbug.com/836141 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2018-6118 – chromium-browser: Use after free in Media Cache
https://notcve.org/view.php?id=CVE-2018-6118
03 May 2018 — A double-eviction in the Incognito mode cache that lead to a user-after-free in cache in Google Chrome prior to 66.0.3359.139 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. Un doble desalojo en la memoria caché en modo Incógnito que llevó a un usuario después de la memoria caché libre en Google Chrome antes de 66.0.3359.139 permitió que un atacante remoto que había comprometido el proceso del renderizador ejecutara código arbitrario a tr... • https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop_26.html • CWE-416: Use After Free •

CVE-2018-6112 – chromium-browser: Incorrect URL handling in DevTools
https://notcve.org/view.php?id=CVE-2018-6112
24 Apr 2018 — Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Hacer que las URL fuesen clicables y permitiendo su formateo en DevTools en Google Chrome, en versiones anteriores a la 66.0.3359.117, permitía que un atacante remoto omitiese las restricciones de navegación mediante una página HTML manipulada. Chromium is an open-source web browser, powered by WebKit. This update upgrad... • http://www.securityfocus.com/bid/103917 • CWE-706: Use of Incorrectly-Resolved Name or Reference •

CVE-2018-6092 – Google Chrome - Integer Overflow when Processing WebAssembly Locals
https://notcve.org/view.php?id=CVE-2018-6092
24 Apr 2018 — An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Un desbordamiento de enteros en sistemas de 32 bits en WebAssembly en Google Chrome, en versiones anteriores a la 66.0.3359.117, permitía que un atacante remoto ejecutase código arbitrario dentro de un sandbox mediante una página HTML manipulada. Chromium is an open-source web browser, powered by WebKit. This update upgrade... • https://packetstorm.news/files/id/148090 • CWE-190: Integer Overflow or Wraparound •

CVE-2018-6096 – chromium-browser: Fullscreen UI spoof
https://notcve.org/view.php?id=CVE-2018-6096
24 Apr 2018 — A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page. Una ventana centrada con JavaScript podría superponerse a la notificación de pantalla completa en Fullscreen en Google Chrome, en versiones anteriores a la 66.0.3359.117, lo que permitía que un atacante remoto ocultase la advertencia de pantalla completa mediante una página HTML manipulada. Chromium i... • http://www.securityfocus.com/bid/103917 • CWE-20: Improper Input Validation •

CVE-2018-6097 – chromium-browser: Fullscreen UI spoof
https://notcve.org/view.php?id=CVE-2018-6097
24 Apr 2018 — Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page. La gestión incorrecta de los métodos asíncronos en Fullscreen en Google Chrome, en versiones anteriores a la 66.0.3359.117 para macOS, permitía que un atacante remoto pudiese entrar en modo de pantalla completa sin mostrar un aviso mediante una página HTML manipulada. Chromium is an open-source web browser,... • http://www.securityfocus.com/bid/103917 • CWE-19: Data Processing Errors •

CVE-2018-6089 – chromium-browser: Same origin policy bypass in Service Worker
https://notcve.org/view.php?id=CVE-2018-6089
24 Apr 2018 — A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page. La falta de comprobación de CORS tras una redirección de un Service Worker a un PDF cross-origin en Service Worker en Google Chrome, en versiones anteriores a la 66.0.3359.117, permitía que un atacante remoto filtrase datos cross-origin limitados mediante una página HTML manipulada. Chrom... • http://www.securityfocus.com/bid/103917 • CWE-20: Improper Input Validation •

CVE-2018-6101 – chromium-browser: Insufficient protection of remote debugging prototol in DevTools
https://notcve.org/view.php?id=CVE-2018-6101
24 Apr 2018 — A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server. La falta de validación del host en DevTools en Google Chrome, en versiones anteriores a la 66.0.3359.117, permitía que un atacante remoto ejecutase código arbitrario mediante una página HTML manipulada si el usuario está ejecutando un servidor de depuración DevTools remoto. Chromium is an open-sou... • http://www.securityfocus.com/bid/103917 • CWE-20: Improper Input Validation •

CVE-2018-6114 – chromium-browser: CSP bypass
https://notcve.org/view.php?id=CVE-2018-6114
24 Apr 2018 — Incorrect enforcement of CSP for

CVE-2018-6110 – chromium-browser: Incorrect handling of plaintext files via file://
https://notcve.org/view.php?id=CVE-2018-6110
24 Apr 2018 — Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page. El análisis de documentos como HTML en Downloads en Google Chrome, en versiones anteriores a la 66.0.3359.117, permitía que un atacante remoto provocase que Chrome ejecutase scripts mediante una página local que no fuese HTML. Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 66.0.3359.117. Iss... • http://www.securityfocus.com/bid/103917 • CWE-20: Improper Input Validation •