Описание
Multiple serious vulnerabilities were found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, spoof user interface.
Below is a complete list of vulnerabilities:
- An out-of-bounds read in V8 can be exploited remotely to execute arbitrary code;
- A use after free in PDFium can be exploited remotely to obtain sensitive information;
- A heap overflow vulnerability in the Skia component can be exploited remotely to execute arbitrary code;
- A use after free in PDFium can be exploited remotely to obtain sensitive information;
- A use after free in Blink can be exploited remotely to obtain sensitive information;
- A heap overflow vulnerability in the Canvas component can be exploited remotely to cause denial of service;
- A use after free in WebAudio can be exploited remotely to bypass security restrictions;
- A use after free in MediaRecorder can be exploited remotely to obtain sensitive information;
- A heap overflow vulnerability in the Blink component can be exploited remotely spoof user interface;
- An out-of-bounds read in V8 can be exploited remotely to cause denial of service;
- A use after free in Skia can be exploited remotely to obtain sensitive information;
- A use after free in Skia can be exploited remotely to obtain sensitive information;
Первичный источник обнаружения
Связанные продукты
- Google-Chrome
- Google-Chrome-Enterprise
- Google-Chrome-Enterprise-for-current-user
- Google-Chrome-for-KIS
- Google-Chrome-for-current-user
Список CVE
- CVE-2018-20070 warning
- CVE-2018-20065 high
- CVE-2018-20068 warning
- CVE-2018-20069 warning
- CVE-2018-20071 warning
- CVE-2018-20067 warning
- CVE-2018-20066 high
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!