News aggregator

CVE-2017-15423

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.
Categories: Security News

CVE-2017-15422

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Categories: Security News

CVE-2017-15418

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Categories: Security News

CVE-2017-15419

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
Categories: Security News

CVE-2017-15420

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Inappropriate implementation in browser navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Categories: Security News

CVE-2017-15417

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Categories: Security News

CVE-2017-15416

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka a Blink out-of-bounds read.
Categories: Security News

CVE-2017-15415

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.
Categories: Security News

CVE-2017-15413

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Categories: Security News

CVE-2017-15412

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Categories: Security News

CVE-2017-15411

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Categories: Security News

CVE-2017-15410

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Categories: Security News

CVE-2017-15409

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Categories: Security News

CVE-2017-15408

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
Categories: Security News

CVE-2017-15407

National Vulnerability Database - Tue, 08/28/2018 - 15:29
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
Categories: Security News

CVE-2018-3926

National Vulnerability Database - Tue, 08/28/2018 - 13:29
An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process incorrectly handles malformed files existing in its data directory, leading to an infinite loop, which eventually causes the process to crash. An attacker can send an HTTP request to trigger this vulnerability.
Categories: Security News

CVE-2014-6047

National Vulnerability Database - Tue, 08/28/2018 - 13:29
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
Categories: Security News

CVE-2014-6048

National Vulnerability Database - Tue, 08/28/2018 - 13:29
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
Categories: Security News

CVE-2014-6049

National Vulnerability Database - Tue, 08/28/2018 - 13:29
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
Categories: Security News

CVE-2014-6050

National Vulnerability Database - Tue, 08/28/2018 - 13:29
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
Categories: Security News

Pages