Show filters
456 Total Results
Displaying 81-90 of 456
Sort by:
Attacker Value
Unknown

CVE-2016-2150

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
0
Attacker Value
Unknown

CVE-2016-0749

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-2335

Disclosure Date: June 07, 2016 (last updated November 08, 2023)
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.
0
Attacker Value
Unknown

CVE-2016-1686

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
0
Attacker Value
Unknown

CVE-2016-1697

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1698

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
0
Attacker Value
Unknown

CVE-2016-1679

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1701

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
0
Attacker Value
Unknown

CVE-2016-1690

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
0
Attacker Value
Unknown

CVE-2016-1675

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
0