|
269741
|
- |
|
google
|
android
|
mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka i…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6616
|
2024-11-21 11:35 |
2015-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269742
|
- |
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2015-6787
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269743
|
- |
|
google
|
chrome
|
The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6786
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269744
|
- |
|
google
|
chrome
|
The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6785
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269745
|
- |
|
google
|
chrome
|
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafte…
|
CWE-20
Improper Input Validation
|
CVE-2015-6784
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269746
|
- |
|
google
|
android
|
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an…
|
CWE-20
Improper Input Validation
|
CVE-2015-6783
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269747
|
- |
|
google
|
chrome
|
The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, wh…
|
CWE-20
Improper Input Validation
|
CVE-2015-6782
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269748
|
- |
|
google
|
chrome
|
Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service or possibly …
|
CWE-189
Numeric Errors
|
CVE-2015-6781
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269749
|
- |
|
google
|
chrome
|
Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a c…
|
NVD-CWE-Other
|
CVE-2015-6780
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269750
|
- |
|
google
|
chrome
|
PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs, which allows remote attackers to bypass intended scheme restrictions via a crafted PDF document, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6779
|
2024-11-21 11:35 |
2015-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|