CVE-2016-5170
- EPSS 0.84%
- Veröffentlicht 25.09.2016 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service ...
CVE-2016-7395
- EPSS 0.63%
- Veröffentlicht 11.09.2016 10:59:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (unin...
CVE-2016-5167
- EPSS 1.59%
- Veröffentlicht 11.09.2016 10:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-5166
- EPSS 0.63%
- Veröffentlicht 11.09.2016 10:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote...
CVE-2016-5165
- EPSS 0.43%
- Veröffentlicht 11.09.2016 10:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the ...
CVE-2016-5164
- EPSS 0.42%
- Veröffentlicht 11.09.2016 10:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary we...
CVE-2016-5163
- EPSS 1.46%
- Veröffentlicht 11.09.2016 10:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted ...
CVE-2016-5162
- EPSS 0.68%
- Veröffentlicht 11.09.2016 10:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resource...
CVE-2016-5161
- EPSS 1.54%
- Veröffentlicht 11.09.2016 10:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attack...
CVE-2016-5160
- EPSS 0.68%
- Veröffentlicht 11.09.2016 10:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resource...