CVE-2016-1697
- EPSS 1.35%
- Veröffentlicht 05.06.2016 23:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypa...
CVE-2016-1696
- EPSS 0.98%
- Veröffentlicht 05.06.2016 23:59:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
CVE-2016-1695
- EPSS 1.19%
- Veröffentlicht 05.06.2016 23:59:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1694
- EPSS 0.71%
- Veröffentlicht 05.06.2016 23:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certificat...
CVE-2016-1693
- EPSS 0.9%
- Veröffentlicht 05.06.2016 23:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file v...
CVE-2016-1692
- EPSS 0.75%
- Veröffentlicht 05.06.2016 23:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote...
CVE-2016-1691
- EPSS 1.4%
- Veröffentlicht 05.06.2016 23:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoin...
CVE-2016-1690
- EPSS 1.48%
- Veröffentlicht 05.06.2016 23:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possi...
CVE-2016-1689
- EPSS 1.73%
- Veröffentlicht 05.06.2016 23:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
CVE-2016-1688
- EPSS 4.87%
- Veröffentlicht 05.06.2016 23:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via craf...