← לוח פגיעויות

CVE-2018-6065

גבוהה 8.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Google Chromium V8 Integer Overflow Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
60% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-190

מוצרים מושפעים

google: chrome; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation; debian: debian linux; mi: mi6 browser

קישורים