- EPSS 1.32%
- Published 30.04.2016 17:59:03
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or...
- EPSS 1.32%
- Published 30.04.2016 17:59:02
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
- EPSS 2.37%
- Published 18.04.2016 10:59:08
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1656
- EPSS 0.4%
- Published 18.04.2016 10:59:05
- Last modified 12.04.2025 10:46:40
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
CVE-2016-1655
- EPSS 3.03%
- Published 18.04.2016 10:59:04
- Last modified 12.04.2025 10:46:40
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted e...
CVE-2016-1654
- EPSS 2.49%
- Published 18.04.2016 10:59:03
- Last modified 12.04.2025 10:46:40
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
CVE-2016-1653
- EPSS 1.52%
- Published 18.04.2016 10:59:02
- Last modified 12.04.2025 10:46:40
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that tri...
CVE-2016-1652
- EPSS 0.51%
- Published 18.04.2016 10:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script o...
CVE-2016-1651
- EPSS 1.39%
- Published 18.04.2016 10:59:00
- Last modified 12.04.2025 10:46:40
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory...
CVE-2016-2802
- EPSS 0.79%
- Published 13.03.2016 18:59:41
- Last modified 12.04.2025 10:46:40
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have ...