Show filters
1,398 Total Results
Displaying 281-290 of 1,398
Sort by:
Attacker Value
Unknown

CVE-2016-1668

Disclosure Date: May 14, 2016 (last updated November 08, 2023)
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
0
Attacker Value
Unknown

CVE-2016-1665

Disclosure Date: May 14, 2016 (last updated November 08, 2023)
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1669

Disclosure Date: May 14, 2016 (last updated November 08, 2023)
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
Attacker Value
Unknown

CVE-2016-4024

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.
0
Attacker Value
Unknown

CVE-2016-4117

Disclosure Date: May 11, 2016 (last updated July 17, 2024)
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
Attacker Value
Unknown

CVE-2016-3718

Disclosure Date: May 05, 2016 (last updated July 25, 2024)
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Attacker Value
Unknown

CVE-2016-4008

Disclosure Date: May 05, 2016 (last updated November 08, 2023)
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
0
Attacker Value
Unknown

CVE-2016-3715

Disclosure Date: May 05, 2016 (last updated July 25, 2024)
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Attacker Value
Unknown

CVE-2016-3714

Disclosure Date: May 05, 2016 (last updated September 11, 2024)
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
Attacker Value
Unknown

CVE-2016-2105

Disclosure Date: May 05, 2016 (last updated November 08, 2023)
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.