Kaspersky ID:
KLA11598
Дата обнаружения:
04/12/2018
Обновлено:
22/01/2024

Описание

Multiple serious vulnerabilities were found in Google Chrome. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. An out-of-bounds read in V8 can be exploited remotely to execute arbitrary code;
  2. A use after free in PDFium can be exploited remotely to obtain sensitive information;
  3. A heap overflow vulnerability in the Skia component can be exploited remotely to execute arbitrary code;
  4. A use after free in PDFium can be exploited remotely to obtain sensitive information;
  5. A use after free in Blink can be exploited remotely to obtain sensitive information;
  6. A heap overflow vulnerability in the Canvas component can be exploited remotely to cause denial of service;
  7. A use after free in WebAudio can be exploited remotely to bypass security restrictions;
  8. A use after free in MediaRecorder can be exploited remotely to obtain sensitive information;
  9. A heap overflow vulnerability in the Blink component can be exploited remotely spoof user interface;
  10. An out-of-bounds read in V8 can be exploited remotely to cause denial of service;
  11. A use after free in Skia can be exploited remotely to obtain sensitive information;
  12. A use after free in Skia can be exploited remotely to obtain sensitive information;

Первичный источник обнаружения

Связанные продукты

Список CVE

  • CVE-2018-20070
    warning
  • CVE-2018-20065
    high
  • CVE-2018-20068
    warning
  • CVE-2018-20069
    warning
  • CVE-2018-20071
    warning
  • CVE-2018-20067
    warning
  • CVE-2018-20066
    high

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Confirm changes?
Your message has been sent successfully.