Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2016-3861

    LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to exec... Read more

    Affected Products : android
    • EPSS Score: %12.45
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-3859

    The Qualcomm camera driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28815326 and Qualcomm internal bug CR1034641.... Read more

    Affected Products : android
    • EPSS Score: %0.07
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-3858

    Buffer overflow in drivers/soc/qcom/subsystem_restart.c in the Qualcomm subsystem driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application that provides a long string, aka Android interna... Read more

    Affected Products : android
    • EPSS Score: %0.07
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-7395

    SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitial... Read more

    Affected Products : chrome
    • EPSS Score: %0.59
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5167

    Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.75
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 3.1

    LOW
    CVE-2016-5166

    The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote atta... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.63
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-5165

    Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the setti... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.50
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-5164

    Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web scr... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.48
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-5163

    The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted right... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.27
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-5162

    The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.68
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5161

    The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers t... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.83
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-5160

    The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.68
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5159

    Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecif... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.26
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5158

    Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.75
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5157

    Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafte... Read more

    Affected Products : fedora leap chrome
    • EPSS Score: %6.59
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5156

    extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attackers ... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.68
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-5155

    Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.... Read more

    Affected Products : leap chrome
    • EPSS Score: %0.77
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5154

    Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted ... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.05
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5153

    The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destr... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.83
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5152

    Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-ba... Read more

    Affected Products : leap chrome
    • EPSS Score: %1.00
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291728 Results