Show filters
374 Total Results
Displaying 51-60 of 374
Sort by:
Attacker Value
Unknown

CVE-2016-1697

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1698

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
0
Attacker Value
Unknown

CVE-2016-1679

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1701

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
0
Attacker Value
Unknown

CVE-2016-1690

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
0
Attacker Value
Unknown

CVE-2016-1675

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
0
Attacker Value
Unknown

CVE-2016-1699

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
0
Attacker Value
Unknown

CVE-2016-1703

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2016-1682

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.
0
Attacker Value
Unknown

CVE-2016-1700

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to extensions.
0