Show filters
1,398 Total Results
Displaying 271-280 of 1,398
Sort by:
Attacker Value
Unknown
CVE-2015-8866
Disclosure Date: May 22, 2016 (last updated November 08, 2023)
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
0
Attacker Value
Unknown
CVE-2016-4348
Disclosure Date: May 20, 2016 (last updated November 25, 2024)
The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
0
Attacker Value
Unknown
CVE-2016-1664
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to spoof the address bar via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-1661
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site, related to BindingSecurity.cpp and DOMWindow.cpp.
0
Attacker Value
Unknown
CVE-2016-1662
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-1663
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-1670
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a renderer process and reusing a request ID.
0
Attacker Value
Unknown
CVE-2016-1666
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-1660
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-1667
Disclosure Date: May 14, 2016 (last updated November 08, 2023)
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
0