CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2017-6296

    Last Modified: 21 Nov 2024

    NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2017-6280

    Last Modified: 21 Nov 2024

    NVIDIA driver contains a possible out-of-bounds read vulnerability due to a leak which may lead to information disclosure. This issue is rated as moderate. Android: A-63851980.

    Published: 6 Mar 2018
    5.5
    Medium

    CVE-2017-6283

    Last Modified: 21 Nov 2024

    NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.

    Published: 6 Mar 2018
    8.4
    High

    CVE-2017-6295

    Last Modified: 21 Nov 2024

    NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is rated as high.

    Published: 6 Mar 2018
    5.5
    Medium

    CVE-2017-6284

    Last Modified: 21 Nov 2024

    NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as moderate.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2017-9783

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-7307

    Last Modified: 21 Nov 2024

    The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.

    Published: 6 Mar 2018
    4.8
    Medium

    CVE-2018-7650

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitize user supplied input to the name parameter, and renders injected JavaScript code to the user's browser. This is different from CVE-2018-6878.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9264

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.

    Published: 6 Mar 2018
    5.3
    Medium

    CVE-2018-9159

    Last Modified: 21 Nov 2024

    In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6057

    Last Modified: 21 Nov 2024

    Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6058

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11215. Reason: This candidate is a reservation duplicate of CVE-2017-11215. Notes: All CVE users should reference CVE-2017-11215 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6059

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11225. Reason: This candidate is a reservation duplicate of CVE-2017-11225. Notes: All CVE users should reference CVE-2017-11225 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6060

    Last Modified: 21 Nov 2024

    Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-6061

    Last Modified: 21 Nov 2024

    A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6062

    Last Modified: 21 Nov 2024

    Heap overflow write in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6063

    Last Modified: 21 Nov 2024

    Incorrect use of mojo::WrapSharedMemoryHandle in Mojo in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6064

    Last Modified: 21 Nov 2024

    Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-6069

    Last Modified: 21 Nov 2024

    Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6071

    Last Modified: 21 Nov 2024

    An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6072

    Last Modified: 21 Nov 2024

    An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6073

    Last Modified: 21 Nov 2024

    A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6076

    Last Modified: 21 Nov 2024

    Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.

    Published: 6 Mar 2018
    4.3
    Medium

    CVE-2018-6078

    Last Modified: 21 Nov 2024

    Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6083

    Last Modified: 21 Nov 2024

    Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9266

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-isup.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9270

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/oids.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9273

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak.

    Published: 6 Mar 2018
    5.3
    Medium

    CVE-2018-1062

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9268

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9272

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-h223.c has a memory leak.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6065

    Last Modified: 24 Oct 2025

    Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Mar 2018
    4.3
    Medium

    CVE-2018-6068

    Last Modified: 21 Nov 2024

    Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6074

    Last Modified: 21 Nov 2024

    Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-6075

    Last Modified: 21 Nov 2024

    Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-6079

    Last Modified: 21 Nov 2024

    Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 6 Mar 2018
    4.7
    Medium

    CVE-2018-6082

    Last Modified: 21 Nov 2024

    Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-7727

    Last Modified: 10 Jul 2025

    An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9265

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9267

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9269

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-giop.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9271

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-multipart.c has a memory leak.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-9274

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, ui/failure_message.c has a memory leak.

    Published: 6 Mar 2018
    7.1
    High

    CVE-2017-1002102

    Last Modified: 21 Nov 2024

    In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-6077

    Last Modified: 21 Nov 2024

    Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-6066

    Last Modified: 21 Nov 2024

    Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-6067

    Last Modified: 21 Nov 2024

    Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6070

    Last Modified: 21 Nov 2024

    Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-6080

    Last Modified: 21 Nov 2024

    Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6081

    Last Modified: 21 Nov 2024

    XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.

    Published: 6 Mar 2018