13,751 CVEs • 235 products
Products (235)
Click to collapseToggle
Products (235)
Click to collapse
CVEs (13,751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings...Show more |
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/f...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 May 14, 2016 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requ...Show more |
5Canonical DebianGoogle+2 more6Chrome Debian LinuxNode.js+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to caus...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption oper...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information vi...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buf...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (us...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.0 HIGH· v3 8.3 HIGH· v2 Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write)...Show more |
wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service...Show more |
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka in...Show more |
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka int...Show more |
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted...Show more |
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted...Show more |