Google

Chrome

3866 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 17.02.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

  • EPSS 0.58%
  • Veröffentlicht 17.02.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.

  • EPSS 0.11%
  • Veröffentlicht 17.02.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted H...

  • EPSS 0.48%
  • Veröffentlicht 19.01.2017 05:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption or DoS via a crafted PDF file.

  • EPSS 0.23%
  • Veröffentlicht 19.01.2017 05:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to bypass the Same Origin Policy via a crafted...

  • EPSS 0.23%
  • Veröffentlicht 19.01.2017 05:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page.

  • EPSS 0.16%
  • Veröffentlicht 19.01.2017 05:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascri...

  • EPSS 0.22%
  • Veröffentlicht 19.01.2017 05:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page.

  • EPSS 0.62%
  • Veröffentlicht 19.01.2017 05:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including t...

  • EPSS 0.62%
  • Veröffentlicht 19.01.2017 05:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML pag...