CVE-2016-5175
- EPSS 0.5%
- Veröffentlicht 25.09.2016 20:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-5174
- EPSS 1.13%
- Veröffentlicht 25.09.2016 20:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) vi...
CVE-2016-5173
- EPSS 0.75%
- Veröffentlicht 25.09.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass...
CVE-2016-5172
- EPSS 1.13%
- Veröffentlicht 25.09.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
CVE-2016-5171
- EPSS 0.84%
- Veröffentlicht 25.09.2016 20:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifi...
CVE-2016-5170
- EPSS 0.84%
- Veröffentlicht 25.09.2016 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service ...
CVE-2016-7395
- EPSS 0.63%
- Veröffentlicht 11.09.2016 10:59:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (unin...
CVE-2016-5167
- EPSS 1.59%
- Veröffentlicht 11.09.2016 10:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-5166
- EPSS 0.63%
- Veröffentlicht 11.09.2016 10:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote...
CVE-2016-5165
- EPSS 0.43%
- Veröffentlicht 11.09.2016 10:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the ...