Google

Chrome

3758 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.07%
  • Veröffentlicht 01.08.2016 02:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attackers to cause a denial of service (heap-based buffer overflow and use-after-free) by leveraging an unr...

  • EPSS 1%
  • Veröffentlicht 23.07.2016 19:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and do...

  • EPSS 1.99%
  • Veröffentlicht 23.07.2016 19:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors re...

  • EPSS 0.75%
  • Veröffentlicht 23.07.2016 19:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote attackers to bypass the ...

  • EPSS 1.18%
  • Veröffentlicht 23.07.2016 19:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating ...

  • EPSS 0.64%
  • Veröffentlicht 23.07.2016 19:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server ...

  • EPSS 1.31%
  • Veröffentlicht 23.07.2016 19:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via ...

  • EPSS 3.87%
  • Veröffentlicht 23.07.2016 19:59:13
  • Zuletzt bearbeitet 04.12.2025 17:15:49

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

  • EPSS 1.11%
  • Veröffentlicht 23.07.2016 19:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.

  • EPSS 2.44%
  • Veröffentlicht 23.07.2016 19:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via cr...