Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
google sfntly - vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2016-1710
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote malicious users to bypass the Same Origin Policy via a crafted w...
Google Chrome
8.8
CVSSv3
CVE-2016-1711
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote malicious users to bypass the Same Origin Policy via a crafted web site.
Google Chrome
8.8
CVSSv3
CVE-2016-5131
Use-after-free vulnerability in libxml2 up to and including 2.9.4, as used in Google Chrome prior to 52.0.2743.82, allows remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
Google Chrome
Xmlsoft Libxml2
Apple Watchos
Apple Tvos
Apple Iphone Os
Apple Mac Os X
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Redhat Enterprise Linux Desktop 6.0
Redhat Enterprise Linux Server 6.0
Redhat Enterprise Linux Workstation 6.0
Suse Linux Enterprise 12.0
Opensuse Leap 42.1
Opensuse Opensuse 13.1
Opensuse Opensuse 13.2
Debian Debian Linux 8.0
Debian Debian Linux 9.0
8.8
CVSSv3
CVE-2016-5132
The Service Workers subsystem in Google Chrome prior to 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote malicious users to bypass the Same Origin Policy via an https IFRAME elemen...
Google Chrome
5.3
CVSSv3
CVE-2016-5133
Google Chrome prior to 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle malicious users to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server data stream.
Google Chrome
8.8
CVSSv3
CVE-2016-5134
net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome prior to 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote malicious users to discover credentials by operating a server with a PAC sc...
Google Chrome
6.5
CVSSv3
CVE-2016-5135
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome prior to 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote malicious users to bypass the Content Security Polic...
Google Chrome
8.8
CVSSv3
CVE-2016-5136
Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome prior to 52.0.2743.82 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors related to script deleti...
Google Chrome
4.3
CVSSv3
CVE-2016-5137
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome prior to 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies...
Google Chrome
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege
CVE-2022-48762
CVE-2022-48751
CVE-2024-37079
CVE-2024-30848
LFI
man-in-the-middle
CVE-2022-48736
CVE-2024-30103
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2