Latest CVE Feed
-
7.6
HIGHCVE-2016-7181
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."... Read more
Affected Products : edge- Published: Dec. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2355
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.... Read more
Affected Products : dotcms- Published: Dec. 19, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10005
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.... Read more
Affected Products : solution_manager- Published: Dec. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5193
Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5192
Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5191
Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages,... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-5190
Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, which allowed a remote attacker to perform an out of bounds memory read via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5189
Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted navigation to blob URLs with non-canonical origins, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5188
Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a remote attacker to spoof various parts of browser UI via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5187
Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-5186
Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled objects after a tab crash, which allowed a remote attacker to perform an out of bounds memory read via crafted PDF files.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5185
Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updateLifecyclePhasesInternal(), which allowed a remote attacker to perform an out of bounds memory read via cr... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5184
PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to potentially exploit heap corruption via cr... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5183
A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker to potentially exploit heap corruption via crafted PDF files.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5182
Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, which allowed a remote attacker to potentially exploit heap corruption via crafted HTML pages.... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5181
Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted execution of v8 microtasks while the DOM was in an inconsistent state, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) ... Read more
Affected Products : chrome- Published: Dec. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-9998
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.... Read more
Affected Products : spip- Published: Dec. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-9997
SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.... Read more
Affected Products : spip- Published: Dec. 17, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9951
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the mali... Read more
Affected Products : apport- Published: Dec. 17, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks... Read more
- Published: Dec. 17, 2016
- Modified: Apr. 12, 2025