Latest CVE Feed
-
7.5
HIGHCVE-2014-9747
The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.... Read more
- Published: Jun. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2014-9746
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not ... Read more
- Published: Jun. 07, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-8177
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.... Read more
- Published: Jun. 07, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2015-5041
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.... Read more
- Published: Jun. 06, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1703
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1702
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized ... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1701
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly h... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1700
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1699
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1698
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information ... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1697
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass th... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1696
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1695
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1694
browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification A... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1693
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a ... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1692
WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote atta... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1691
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoinciden... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1690
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly h... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1689
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1688
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted J... Read more
- Published: Jun. 05, 2016
- Modified: Apr. 12, 2025