CVE-2016-5155
- EPSS 0.88%
- Veröffentlicht 11.09.2016 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.
CVE-2016-5153
- EPSS 1.67%
- Veröffentlicht 11.09.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-...
CVE-2016-5152
- EPSS 1%
- Veröffentlicht 11.09.2016 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (he...
CVE-2016-5151
- EPSS 1.04%
- Veröffentlicht 11.09.2016 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PD...
CVE-2016-5150
- EPSS 1.42%
- Veröffentlicht 11.09.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly r...
CVE-2016-5149
- EPSS 1.31%
- Veröffentlicht 11.09.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injecti...
CVE-2016-5148
- EPSS 0.57%
- Veröffentlicht 11.09.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates...
CVE-2016-5147
- EPSS 0.58%
- Veröffentlicht 11.09.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS ...
CVE-2016-7153
- EPSS 1.25%
- Veröffentlicht 06.09.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-pa...
CVE-2016-7152
- EPSS 1.25%
- Veröffentlicht 06.09.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-par...