Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
google sfntly - vulnerabilities and exploits
(subscribe to this query)
9.3
CVSSv2
CVE-2016-1706
The PPAPI implementation in Google Chrome prior to 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote malicious users to bypass a sandbox protection mechanism via an unexpected...
Google Chrome
6.8
CVSSv2
CVE-2017-0713
A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.
Google Android 4.0
Google Android 4.0.1
Google Android 4.0.2
Google Android 4.0.3
Google Android 7.0
Google Android 7.1.1
Google Android 5.1
Google Android 5.1.1
Google Android 4.0.4
Google Android 4.1.2
Google Android 4.4.1
Google Android 4.4.3
Google Android 6.0
Google Android 6.0.1
Google Android 5.0
Google Android 5.0.1
Google Android 4.2.1
Google Android 4.2.2
Google Android 4.3
Google Android 4.3.1
Google Android 7.1.0
Google Android 7.1.2
6.8
CVSSv2
CVE-2016-1708
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome prior to 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote malicious users to cause a denial of service (use-after-free) or...
Google Chrome
6.8
CVSSv2
CVE-2016-1709
Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly prior to 2016-06-10, as used in Google Chrome prior to 52.0.2743.82, allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a crafted S...
Google Sfntly -
Google Chrome
6.8
CVSSv2
CVE-2016-1710
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote malicious users to bypass the Same Origin Policy via a crafted w...
Google Chrome
6.8
CVSSv2
CVE-2016-1711
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote malicious users to bypass the Same Origin Policy via a crafted web site.
Google Chrome
6.8
CVSSv2
CVE-2016-5127
Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, allows remote malicious users to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code involving an @imp...
Google Chrome
6.8
CVSSv2
CVE-2016-5128
objects.cc in Google V8 prior to 5.2.361.27, as used in Google Chrome prior to 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote malicious users to bypass the Same Origin Policy via a crafted web site.
Google Chrome
Google V8 5.2.360
6.8
CVSSv2
CVE-2016-5129
Google V8 prior to 5.2.361.32, as used in Google Chrome prior to 52.0.2743.82, does not properly process left-trimmed objects, which allows remote malicious users to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript cod...
Google Chrome 51.0.2704.106
Google V8
6.8
CVSSv2
CVE-2016-5131
Use-after-free vulnerability in libxml2 up to and including 2.9.4, as used in Google Chrome prior to 52.0.2743.82, allows remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
Google Chrome
Xmlsoft Libxml2
Apple Watchos
Apple Tvos
Apple Iphone Os
Apple Mac Os X
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Redhat Enterprise Linux Desktop 6.0
Redhat Enterprise Linux Server 6.0
Redhat Enterprise Linux Workstation 6.0
Suse Linux Enterprise 12.0
Opensuse Leap 42.1
Opensuse Opensuse 13.1
Opensuse Opensuse 13.2
Debian Debian Linux 8.0
Debian Debian Linux 9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »