Show filters
156 Total Results
Displaying 31-40 of 156
Sort by:
Attacker Value
Unknown
CVE-2016-2834
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-5118
Disclosure Date: June 10, 2016 (last updated November 20, 2024)
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
0
Attacker Value
Unknown
CVE-2016-1697
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
0
Attacker Value
Unknown
CVE-2016-1679
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
0
Attacker Value
Unknown
CVE-2016-1675
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
0
Attacker Value
Unknown
CVE-2016-1699
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
0
Attacker Value
Unknown
CVE-2016-1703
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-1682
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.
0
Attacker Value
Unknown
CVE-2016-1702
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data.
0
Attacker Value
Unknown
CVE-2016-1677
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
0