Search CVE reports


Toggle filters

391 – 400 of 881 results


CVE-2016-5201

Medium priority

Some fixes available 4 of 5

A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2014-9911

Medium priority

Some fixes available 2 of 11

Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have...

8 affected packages

android, chromium-browser, firefox, icu, mozjs24...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android — Not in release Not in release Not in release Not in release
chromium-browser — Not affected Not affected Not in release Not affected
firefox — Not affected Not affected Not in release Not affected
icu — Not affected Not affected Not affected Not affected
mozjs24 — Not in release Not in release Not in release Not in release
oxide-qt — Not in release Not in release Not in release Not in release
r-cran-stringi — Not affected Not affected Not affected Not affected
thunderbird — Not affected Not affected Not in release Not affected
Show all 8 packages Show less packages

CVE-2016-5193

Medium priority
Ignored

Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2016-5191

Medium priority

Some fixes available 4 of 5

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or...

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2016-5190

Medium priority

Some fixes available 4 of 5

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, which allowed a remote attacker to perform an out of bounds memory read via crafted...

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2016-5184

Medium priority

Some fixes available 4 of 5

PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to potentially...

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2016-5183

Medium priority

Some fixes available 4 of 5

A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker to potentially exploit heap corruption via crafted PDF files.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2016-9652

Medium priority

Some fixes available 8 of 9

Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages

CVE-2016-9651

Medium priority

Some fixes available 12 of 18

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
libv8 — — — — Not in release
libv8-3.14 — — — — Ignored
oxide-qt — — — — Not in release
Show less packages

CVE-2016-9650

Medium priority

Some fixes available 8 of 9

Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — —
oxide-qt — — — — —
Show less packages