ALT-PU-2018-1126-1
Closed vulnerabilities
BDU:2018-01520
Уязвимость компонента Catalog Service браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2018-01521
Уязвимость компонента External Protocol Handler браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2018-01522
Уязвимость компонента Download File Handler браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2017-15420
Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- 1040282
- 1040282
- RHSA-2017:3401
- RHSA-2017:3401
- https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
- https://crbug.com/777419
- https://crbug.com/777419
- GLSA-201801-03
- GLSA-201801-03
- DSA-4064
- DSA-4064
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6031
Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/780450
- https://crbug.com/780450
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6032
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/787103
- https://crbug.com/787103
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6033
Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted Chrome Extension.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/793620
- https://crbug.com/793620
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6034
Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/784183
- https://crbug.com/784183
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6035
Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/797500
- https://crbug.com/797500
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6036
Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user data via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/789952
- https://crbug.com/789952
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6037
Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/753645
- https://crbug.com/753645
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6038
Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/774174
- https://crbug.com/774174
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6039
Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/775527
- https://crbug.com/775527
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6040
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security policy via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/778658
- https://crbug.com/778658
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6041
Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/760342
- https://crbug.com/760342
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6042
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/773930
- https://crbug.com/773930
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6043
Insufficient data validation in External Protocol Handler in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially execute arbitrary programs on user machine via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/785809
- https://crbug.com/785809
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6045
Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/797497
- https://crbug.com/797497
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6046
Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/798163
- https://crbug.com/798163
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6047
Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/799847
- https://crbug.com/799847
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6048
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/763194
- https://crbug.com/763194
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6049
Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/774438
- https://crbug.com/774438
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6050
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/774842
- https://crbug.com/774842
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6051
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/441275
- https://crbug.com/441275
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6052
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/615608
- https://crbug.com/615608
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6053
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/758169
- https://crbug.com/758169
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6054
Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
- 102797
- 102797
- 1040282
- 1040282
- RHSA-2018:0265
- RHSA-2018:0265
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.html
- https://crbug.com/797511
- https://crbug.com/797511
- DSA-4103
- DSA-4103
Modified: 2024-11-21
CVE-2018-6055
Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted HTML page.
Modified: 2024-11-21
CVE-2018-6119
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.