ALT-PU-2018-2457-1
Closed vulnerabilities
Published: 2019-01-09
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-17458
An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Severity: MEDIUM (6.8)
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Severity: HIGH (8.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- https://access.redhat.com/errata/RHSA-2018:2818
- https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop_11.html
- https://crbug.com/875322
- https://access.redhat.com/errata/RHSA-2018:2818
- https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop_11.html
- https://crbug.com/875322
Published: 2019-01-09
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-17459
Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Severity: MEDIUM (4.3)
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: MEDIUM (6.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
References:
- https://access.redhat.com/errata/RHSA-2018:2818
- https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop_11.html
- https://crbug.com/880759
- https://access.redhat.com/errata/RHSA-2018:2818
- https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop_11.html
- https://crbug.com/880759