|
1141
|
5.3
5.0
|
MEDIUM
Network
|
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong…
|
NVD-CWE-noinfo
|
CVE-2018-5117
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 13:08
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1142
|
9.8
7.5
|
CRITICAL
Network
|
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in…
|
CWE-190 CWE-908
Integer Overflow or Wraparound Use of Uninitialized Resource
|
CVE-2018-5095
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 13:08
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1143
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This …
|
CWE-416
Use After Free
|
CVE-2017-7809
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1144
|
8.1
5.8
|
HIGH
Network
|
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifes…
|
CWE-20
Improper Input Validation
|
CVE-2017-7807
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1145
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exp…
|
CWE-416
Use After Free
|
CVE-2017-7802
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1146
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potenti…
|
CWE-416
Use After Free
|
CVE-2017-7801
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1147
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulne…
|
CWE-416
Use After Free
|
CVE-2017-7800
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1148
|
8.8
6.8
|
HIGH
Network
|
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when open…
|
CWE-94
Code Injection
|
CVE-2017-7798
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1149
|
9.8
7.5
|
CRITICAL
Network
|
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. T…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7792
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1150
|
5.3
5.0
|
MEDIUM
Network
|
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert fr…
|
CWE-20
Improper Input Validation
|
CVE-2017-7791
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|