CVE-2016-5156
- EPSS 1.68%
- Veröffentlicht 11.09.2016 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attac...
CVE-2016-5154
- EPSS 1.05%
- Veröffentlicht 11.09.2016 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a cra...
CVE-2016-5155
- EPSS 0.77%
- Veröffentlicht 11.09.2016 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.
CVE-2016-5153
- EPSS 1.83%
- Veröffentlicht 11.09.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-...
CVE-2016-5152
- EPSS 1%
- Veröffentlicht 11.09.2016 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (he...
CVE-2016-5151
- EPSS 1.04%
- Veröffentlicht 11.09.2016 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PD...
CVE-2016-5150
- EPSS 1.55%
- Veröffentlicht 11.09.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly r...
CVE-2016-5149
- EPSS 1.31%
- Veröffentlicht 11.09.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injecti...
CVE-2016-5148
- EPSS 0.67%
- Veröffentlicht 11.09.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates...
CVE-2016-5147
- EPSS 0.85%
- Veröffentlicht 11.09.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS ...