2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6126A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m...
CVE-2018-6124Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potential...
CVE-2018-6123A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap c...
CVE-2018-6120An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior ...
CVE-2018-6117Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially s...
CVE-2018-6114Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke...
CVE-2018-6113Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a r...
CVE-2018-6112Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remot...
CVE-2018-6111An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local ...
CVE-2018-6110Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome...
CVE-2018-6109readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in ...
CVE-2018-6106An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote ...
CVE-2018-6100Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a ...
CVE-2018-6097Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remo...
CVE-2018-6096A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359....
CVE-2018-6093Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-orig...
CVE-2018-6091Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google Chrome prior to 66.0...
CVE-2018-6084Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local...
CVE-2018-6056Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote ...
CVE-2018-20071Insufficiently strict origin checks during JIT payment app installation in Payments in Google Chrome prior to 70.0.3538....
CVE-2018-20070Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att...
CVE-2018-20069Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allo...
CVE-2018-20068Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to...
CVE-2018-20067A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Navigation in Google C...
CVE-2018-20066Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now