|
268631
|
5.3 |
MEDIUM
Network
|
theforeman
|
foreman
|
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtai…
|
CWE-200
Information Exposure
|
CVE-2016-4995
|
2024-11-21 11:53 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268632
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-5146
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268633
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, …
|
CWE-254
7PK - Security Features
|
CVE-2016-5145
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268634
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which…
|
CWE-284
Improper Access Control
|
CVE-2016-5144
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268635
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5143
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268636
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial o…
|
CWE-416
Use After Free
|
CVE-2016-5142
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268637
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.…
|
CWE-20
Improper Input Validation
|
CVE-2016-5141
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268638
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5140
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268639
|
7.6 |
HIGH
Network
|
google
|
chrome
|
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-b…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5139
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268640
|
9.1 |
CRITICAL
Network
|
libgd opensuse debian
|
libgd leap debian_linux
|
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memor…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5116
|
2024-11-21 11:53 |
2016-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|