Latest CVE Feed
-
8.8
HIGHCVE-2016-7549
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possib... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5175
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5174
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) via a c... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-5173
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the ... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5172
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5171
WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified ot... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5170
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (use-... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5169
Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.... Read more
Affected Products : chrome_os- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4779
Apple Type Services (ATS) in Apple OS X before 10.12 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4778
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4777
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (invalid pointer dereference) via a crafted app.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-4776
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than C... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4775
The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS before 3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-4774
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than C... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-4773
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than C... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4772
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to cause a denial of service (unintended lock) via unspecified vectors.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-4771
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4769
WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4768
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than ... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4767
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than ... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025