Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
google sfntly - vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2016-5136
Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome prior to 52.0.2743.82 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors related to script deleti...
Google Chrome
6.8
CVSSv2
CVE-2016-1709
Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly prior to 2016-06-10, as used in Google Chrome prior to 52.0.2743.82, allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a crafted S...
Google Sfntly -
Google Chrome
6.8
CVSSv2
CVE-2016-1710
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote malicious users to bypass the Same Origin Policy via a crafted w...
Google Chrome
4.3
CVSSv2
CVE-2016-1707
ios/web/web_state/ui/crw_web_controller.mm in Google Chrome prior to 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote malicious users to spoof the URL display via a crafted web site.
Google Chrome
4.3
CVSSv2
CVE-2016-5130
content/renderer/history_controller.cc in Google Chrome prior to 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote malicious users to spoof the URL display via a crafted web site.
Google Chrome
4.3
CVSSv2
CVE-2016-5133
Google Chrome prior to 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle malicious users to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server data stream.
Google Chrome
4.3
CVSSv2
CVE-2016-5134
net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome prior to 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote malicious users to discover credentials by operating a server with a PAC sc...
Google Chrome
4.3
CVSSv2
CVE-2016-5135
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote malicious users to bypass the Content Security Polic...
Google Chrome
4.3
CVSSv2
CVE-2016-5137
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome prior to 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies...
Google Chrome
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2018-25103
CVE-2024-36279
CVE-2024-38457
elevation of privilege
CVE-2024-27801
CVE-2024-30103
NULL pointer dereference
CVE-2024-6057
XML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2