CVE-2014-9747
- EPSS 1.1%
- Veröffentlicht 07.06.2016 14:06:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.
CVE-2014-9746
- EPSS 0.84%
- Veröffentlicht 07.06.2016 14:06:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do...
CVE-2016-1703
- EPSS 0.94%
- Veröffentlicht 05.06.2016 23:59:33
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1702
- EPSS 1.31%
- Veröffentlicht 05.06.2016 23:59:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serial...
CVE-2016-1701
- EPSS 1.57%
- Veröffentlicht 05.06.2016 23:59:31
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possi...
CVE-2016-1700
- EPSS 1.99%
- Veröffentlicht 05.06.2016 23:59:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly...
CVE-2016-1699
- EPSS 0.9%
- Veröffentlicht 05.06.2016 23:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.ap...
CVE-2016-1698
- EPSS 0.65%
- Veröffentlicht 05.06.2016 23:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive informa...
CVE-2016-1697
- EPSS 1.84%
- Veröffentlicht 05.06.2016 23:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypa...
CVE-2016-1696
- EPSS 1.45%
- Veröffentlicht 05.06.2016 23:59:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.