Latest CVE Feed
-
6.1
MEDIUMCVE-2016-5164
Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web scr... Read more
- EPSS Score: %0.48
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5163
The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted right... Read more
- EPSS Score: %1.27
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5162
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more
- EPSS Score: %0.68
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5161
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers t... Read more
- EPSS Score: %1.83
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5160
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more
- EPSS Score: %0.68
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5159
Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecif... Read more
- EPSS Score: %1.26
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5158
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based... Read more
- EPSS Score: %0.75
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5157
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafte... Read more
- EPSS Score: %6.59
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5156
extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attackers ... Read more
- EPSS Score: %1.68
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5155
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.... Read more
- EPSS Score: %0.77
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5154
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted ... Read more
- EPSS Score: %1.05
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5153
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destr... Read more
- EPSS Score: %1.83
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5152
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-ba... Read more
- EPSS Score: %1.00
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5151
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF doc... Read more
- EPSS Score: %1.04
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5150
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restri... Read more
- EPSS Score: %1.55
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5149
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection at... Read more
- EPSS Score: %1.31
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5148
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka... Read more
Affected Products : chrome- EPSS Score: %0.67
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5147
Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS... Read more
Affected Products : chrome- EPSS Score: %0.85
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6212
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.... Read more
Affected Products : drupal- EPSS Score: %0.35
- Published: Sep. 09, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-6211
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.... Read more
- EPSS Score: %1.18
- Published: Sep. 09, 2016
- Modified: Apr. 12, 2025