8.8
CVSSv3

CVE-2018-18356

Published: 11/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An integer overflow in path handling lead to a use after free in Skia in Google Chrome before 71.0.3578.80 allowed a remote malicious user to potentially exploit heap corruption via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server tus 7.6

redhat enterprise linux server eus 7.6

redhat enterprise linux server aus 7.6

opensuse leap 15.0

Vendor Advisories

Several security issues were fixed in Thunderbird ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Synopsis Important: firefox security update Type/Severity Security Advisory: Important Topic An update for firefox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: firefox security update Type/Severity Security Advisory: Important Topic An update for firefox is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2018-17480 Guang Gong discovered an out-of-bounds write issue in the v8 javascript library CVE-2018-17481 Several use-after-free issues were discovered in the pdfium library CVE-2018-18335 A buffer overflow issue was discovered in the skia library CVE- ...
Multiple security issues have been found in the Thunderbird mail client, which could lead to the execution of arbitrary code, denial of service or spoofing of S/MIME signatures For the stable distribution (stretch), these problems have been fixed in version 1:6051-1~deb9u1 We recommend that you upgrade your thunderbird packages For the detaile ...
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 710357880 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page ...
A use-after-free has been found in the Skia component of chromium before 710357880 and firefox before 6501 ...
Mozilla Foundation Security Advisory 2019-04 Security vulnerabilities fixed in Firefox 6501 Announced February 12, 2019 Impact high Products Firefox Fixed in Firefox 6501 ...
Mozilla Foundation Security Advisory 2019-05 Security vulnerabilities fixed in Firefox ESR 6051 Announced February 12, 2019 Impact high Products Firefox ESR Fixed in Firefox ESR 6051 ...
Mozilla Foundation Security Advisory 2019-06 Security vulnerabilities fixed in Thunderbird 6051 Announced February 14, 2019 Impact high Products Thunderbird Fixed in Thunderbird 6051 ...