Latest CVE Feed
-
6.5
MEDIUMCVE-2016-5162
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5161
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers t... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5160
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources fie... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5159
Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecif... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5158
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5157
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafte... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5156
extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attackers ... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5155
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5154
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted ... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5153
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destr... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5152
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-ba... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5151
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF doc... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5150
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restri... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5149
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection at... Read more
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5148
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka... Read more
Affected Products : chrome- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5147
Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS... Read more
Affected Products : chrome- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6212
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.... Read more
Affected Products : drupal- Published: Sep. 09, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-6211
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.... Read more
- Published: Sep. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4573
Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D,... Read more
Affected Products : fortiswitch fsw-1024d fsw-1048d fsw-108d-poe fsw-124d fsw-124d-poe fsw-224d-fpoe fsw-224d-poe fsw-248d-fpoe fsw-248d-poe +12 more products- Published: Sep. 09, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1280
PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D20, 13.3 before 13.3R10, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R7, 15.1 before 15.1... Read more
- Published: Sep. 09, 2016
- Modified: Apr. 12, 2025