CVE-2016-5141
- EPSS 1.1%
- Veröffentlicht 07.08.2016 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.cpp and ScopedPageLoadDeferrer.cpp.
CVE-2016-5140
- EPSS 2.38%
- Veröffentlicht 07.08.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafte...
CVE-2016-5139
- EPSS 1.28%
- Veröffentlicht 07.08.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified ...
CVE-2016-5138
- EPSS 1.07%
- Veröffentlicht 01.08.2016 02:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attackers to cause a denial of service (heap-based buffer overflow and use-after-free) by leveraging an unr...
CVE-2016-5137
- EPSS 1.01%
- Veröffentlicht 23.07.2016 19:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and do...
CVE-2016-5136
- EPSS 1.99%
- Veröffentlicht 23.07.2016 19:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors re...
CVE-2016-5135
- EPSS 0.43%
- Veröffentlicht 23.07.2016 19:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote attackers to bypass the ...
CVE-2016-5134
- EPSS 1.19%
- Veröffentlicht 23.07.2016 19:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating ...
CVE-2016-5133
- EPSS 0.65%
- Veröffentlicht 23.07.2016 19:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server ...
CVE-2016-5132
- EPSS 1.59%
- Veröffentlicht 23.07.2016 19:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via ...