Latest CVE Feed
-
7.8
HIGHCVE-2016-0094
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applic... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0093
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applic... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0092
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Wi... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0091
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Wi... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0087
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly validate handles, which allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."... Read more
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0057
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka "Microsoft Office Security Feature Bypass Vulnerab... Read more
Affected Products : office- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0021
Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."... Read more
Affected Products : infopath- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2845
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visit... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2844
WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote attackers to cause a denial of service (incorrect cast and assertion... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2843
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1642
Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1641
Use-after-free vulnerability in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an image download after a c... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1640
The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which makes it easier for remote attackers to trick a user into believing that an ... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1639
Use-after-free vulnerability in browser/extensions/api/webrtc_audio_private/webrtc_audio_private_api.cc in the WebRTC Audio Private API implementation in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly ha... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1638
extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1637
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1636
The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache information about integrity-check occurrences instead of integrity-check successes, which allows remote atta... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1635
extensions/renderer/render_frame_observer_natives.cc in Google Chrome before 49.0.2623.75 does not properly consider object lifetimes and re-entrancy issues during OnDocumentElementCreated handling, which allows remote attackers to cause a denial of servi... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1634
Use-after-free vulnerability in the StyleResolver::appendCSSStyleSheet function in WebKit/Source/core/css/resolver/StyleResolver.cpp in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibly h... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1633
Use-after-free vulnerability in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.... Read more
Affected Products : chrome- Published: Mar. 06, 2016
- Modified: Apr. 12, 2025