CVE-2016-5131
- EPSS 3.53%
- Veröffentlicht 23.07.2016 19:59:13
- Zuletzt bearbeitet 04.12.2025 17:15:49
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
CVE-2016-5130
- EPSS 1.13%
- Veröffentlicht 23.07.2016 19:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.
CVE-2016-5129
- EPSS 2.47%
- Veröffentlicht 23.07.2016 19:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via cr...
CVE-2016-5128
- EPSS 1.46%
- Veröffentlicht 23.07.2016 19:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a ...
CVE-2016-5127
- EPSS 2.18%
- Veröffentlicht 23.07.2016 19:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript ...
CVE-2016-1711
- EPSS 1.78%
- Veröffentlicht 23.07.2016 19:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to bypass the Same Origin Policy v...
CVE-2016-1710
- EPSS 1.28%
- Veröffentlicht 23.07.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attackers to bypass the Same Origin ...
CVE-2016-1709
- EPSS 1.15%
- Veröffentlicht 23.07.2016 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly before 2016-06-10, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other im...
CVE-2016-1708
- EPSS 1.52%
- Veröffentlicht 23.07.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of servi...
CVE-2016-1707
- EPSS 0.7%
- Veröffentlicht 23.07.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via a crafted web site.