Show filters
185 Total Results
Displaying 11-20 of 185
Sort by:
Attacker Value
Unknown
CVE-2020-6514
Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
0
Attacker Value
Unknown
CVE-2014-3180
Disclosure Date: November 06, 2019 (last updated November 08, 2023)
In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code path is unreachable
0
Attacker Value
Unknown
CVE-2019-16508
Disclosure Date: October 01, 2019 (last updated November 27, 2024)
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.
0
Attacker Value
Unknown
CVE-2016-5179
Disclosure Date: March 07, 2018 (last updated November 08, 2023)
Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.
0
Attacker Value
Unknown
CVE-2017-15397
Disclosure Date: February 07, 2018 (last updated November 08, 2023)
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.
0
Attacker Value
Unknown
CVE-2017-15400
Disclosure Date: February 07, 2018 (last updated November 08, 2023)
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
0
Attacker Value
Unknown
CVE-2017-5084
Disclosure Date: October 27, 2017 (last updated November 08, 2023)
Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.
0
Attacker Value
Unknown
CVE-2016-5169
Disclosure Date: September 25, 2016 (last updated November 08, 2023)
Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-5131
Disclosure Date: July 23, 2016 (last updated November 08, 2023)
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
0
Attacker Value
Unknown
CVE-2015-4000
Disclosure Date: May 21, 2015 (last updated October 23, 2024)
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
0