Opensuse

Leap

1897 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.35%
  • Published 05.06.2016 23:59:31
  • Last modified 12.04.2025 10:46:40

The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possi...

  • EPSS 1.72%
  • Published 05.06.2016 23:59:30
  • Last modified 12.04.2025 10:46:40

extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly...

  • EPSS 0.58%
  • Published 05.06.2016 23:59:29
  • Last modified 12.04.2025 10:46:40

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.ap...

  • EPSS 0.82%
  • Published 05.06.2016 23:59:28
  • Last modified 12.04.2025 10:46:40

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive informa...

  • EPSS 1.35%
  • Published 05.06.2016 23:59:27
  • Last modified 12.04.2025 10:46:40

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypa...

  • EPSS 0.98%
  • Published 05.06.2016 23:59:26
  • Last modified 12.04.2025 10:46:40

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

  • EPSS 1.19%
  • Published 05.06.2016 23:59:25
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 0.71%
  • Published 05.06.2016 23:59:24
  • Last modified 12.04.2025 10:46:40

browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certificat...

  • EPSS 0.9%
  • Published 05.06.2016 23:59:23
  • Last modified 12.04.2025 10:46:40

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file v...

  • EPSS 0.75%
  • Published 05.06.2016 23:59:21
  • Last modified 12.04.2025 10:46:40

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote...