Google

Chrome

3771 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.31%
  • Veröffentlicht 11.09.2016 10:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injecti...

  • EPSS 0.57%
  • Veröffentlicht 11.09.2016 10:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates...

  • EPSS 0.58%
  • Veröffentlicht 11.09.2016 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS ...

  • EPSS 1.25%
  • Veröffentlicht 06.09.2016 10:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-pa...

  • EPSS 1.25%
  • Veröffentlicht 06.09.2016 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-par...

  • EPSS 0.63%
  • Veröffentlicht 07.08.2016 19:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 1%
  • Veröffentlicht 07.08.2016 19:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, which allows remote attackers to bypass the Same Or...

  • EPSS 1.37%
  • Veröffentlicht 07.08.2016 19:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access ...

  • EPSS 1.41%
  • Veröffentlicht 07.08.2016 19:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access ...

  • EPSS 2.84%
  • Veröffentlicht 07.08.2016 19:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspeci...