Show filters
351 Total Results
Displaying 91-100 of 351
Sort by:
Attacker Value
Unknown

CVE-2016-4447

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
0
Attacker Value
Unknown

CVE-2016-1581

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-1582

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4450

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Attacker Value
Unknown

CVE-2016-1697

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1679

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
0
Attacker Value
Unknown

CVE-2016-1675

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
0
Attacker Value
Unknown

CVE-2016-1699

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
0
Attacker Value
Unknown

CVE-2016-1703

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2016-1682

Disclosure Date: June 05, 2016 (last updated November 08, 2023)
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.
0