ZeroHour

CVE-2018-18356

CVSS 3.0
8.8 high
EPSS
3%p88
Published
()
Modified
Description

An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Vendors
googledebiancanonicalredhatopensuse
Products
chrome, debian linux, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, leap
Weakness
CWE-190, CWE-416, CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.