Latest CVE Feed
-
8.8
HIGHCVE-2016-5167
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- EPSS Score: %1.75
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
3.1
LOWCVE-2016-5166
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote atta... Read more
- EPSS Score: %0.63
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5165
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the setti... Read more
- EPSS Score: %0.50
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5164
Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web scr... Read more
- EPSS Score: %0.48
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5163
The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted right... Read more
- EPSS Score: %1.27
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5162
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more
- EPSS Score: %0.68
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5161
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers t... Read more
- EPSS Score: %1.83
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5160
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more
- EPSS Score: %0.68
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5159
Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecif... Read more
- EPSS Score: %1.26
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5158
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based... Read more
- EPSS Score: %0.75
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5157
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafte... Read more
- EPSS Score: %6.59
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5156
extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attackers ... Read more
- EPSS Score: %1.68
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5155
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.... Read more
- EPSS Score: %0.77
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5154
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted ... Read more
- EPSS Score: %1.05
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5153
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destr... Read more
- EPSS Score: %1.83
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5152
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-ba... Read more
- EPSS Score: %1.00
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5151
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF doc... Read more
- EPSS Score: %1.04
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5150
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restri... Read more
- EPSS Score: %1.55
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5149
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection at... Read more
- EPSS Score: %1.31
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5148
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka... Read more
Affected Products : chrome- EPSS Score: %0.67
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025