CVE-2016-5192
- EPSS 0.24%
- Veröffentlicht 18.12.2016 03:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.
CVE-2016-5193
- EPSS 0.28%
- Veröffentlicht 18.12.2016 03:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.
CVE-2005-4900
- EPSS 0.22%
- Veröffentlicht 14.10.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this...
CVE-2016-5176
- EPSS 0.21%
- Veröffentlicht 29.09.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.
CVE-2016-7549
- EPSS 0.86%
- Veröffentlicht 25.09.2016 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or p...
CVE-2016-5175
- EPSS 0.5%
- Veröffentlicht 25.09.2016 20:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-5174
- EPSS 1.13%
- Veröffentlicht 25.09.2016 20:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) vi...
CVE-2016-5173
- EPSS 0.75%
- Veröffentlicht 25.09.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass...
CVE-2016-5172
- EPSS 1.13%
- Veröffentlicht 25.09.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
CVE-2016-5171
- EPSS 0.84%
- Veröffentlicht 25.09.2016 20:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifi...