Latest CVE Feed
-
4.3
MEDIUMCVE-2016-1657
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a ... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1656
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1655
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extens... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1654
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1653
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1652
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTM... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-1651
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or c... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2427
The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via ... Read more
- Published: Apr. 18, 2016
- Modified: May. 12, 2025
-
5.5
MEDIUMCVE-2016-2426
server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive informati... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2425
mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 supports file:///data attachments, which allows attackers to obtain sensitive information via a crafted applicati... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-2424
server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause a denial of service (reboot loop) ... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
6.6
MEDIUMCVE-2016-2423
server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass ... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2422
Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate in an unrelated CA role, which allows attackers to gain privileges via a crafted application, as demonstrat... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
6.6
MEDIUMCVE-2016-2421
Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2420
rootdir/init.rc in Android 4.x before 4.4.4 does not ensure that the /data/tombstones directory exists for the Debuggerd component, which allows attackers to gain privileges via a crafted application, aka internal bug 26403620.... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2419
media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2418
media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mec... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2417
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memor... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2416
libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for the android.permission.DUMP permission, which allows attackers to obtain sensitive informatio... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-2415
exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to obtain sensitive information via a crafted application that trigge... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025