CVEs (97)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unsp...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecif...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a d...Show more |
6Canonical DebianGoogle+3 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overfl...Show more |
6Canonical DebianGoogle+3 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreMay 6, 2026 Jun 5, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and lever...Show more |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vec...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and Loca...Show more |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings...Show more |
3Mozilla OpensuseSuse4Firefox LeapLinux Enterprise+1 moreMay 6, 2026 Apr 30, 2016 N/A· v4 8.8 HIGH· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corrup...Show more |
4Debian MozillaOpensuse+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Apr 30, 2016 N/A· v4 8.8 HIGH· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Google OpensuseSuse3Chrome LeapLinux EnterpriseMay 6, 2026 Apr 18, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors. |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifie...Show more |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors. |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via cr...Show more |
4Debian GoogleOpensuse+1 more4Chrome Debian LinuxLeap+1 moreMay 6, 2026 Apr 18, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to...Show more |
4Debian GoogleOpensuse+1 more4Chrome Debian LinuxLeap+1 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive i...Show more |
5Mozilla OpensuseOracle+2 more6Firefox Graphite2Leap+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffe...Show more |