Google

Chrome

3758 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.9%
  • Veröffentlicht 05.06.2016 23:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file v...

  • EPSS 0.75%
  • Veröffentlicht 05.06.2016 23:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote...

  • EPSS 1.4%
  • Veröffentlicht 05.06.2016 23:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoin...

  • EPSS 1.48%
  • Veröffentlicht 05.06.2016 23:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possi...

  • EPSS 1.73%
  • Veröffentlicht 05.06.2016 23:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.

  • EPSS 4.87%
  • Veröffentlicht 05.06.2016 23:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via craf...

  • EPSS 2.06%
  • Veröffentlicht 05.06.2016 23:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.

  • EPSS 1.45%
  • Veröffentlicht 05.06.2016 23:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of se...

  • EPSS 1.45%
  • Veröffentlicht 05.06.2016 23:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

  • EPSS 0.47%
  • Veröffentlicht 05.06.2016 23:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly hav...