|
266441
|
8.8 |
HIGH
Network
|
opensuse redhat google
|
opensuse enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary chrome
|
The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishand…
|
NVD-CWE-Other
|
CVE-2016-1663
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266442
|
9.8 |
CRITICAL
Network
|
google redhat opensuse
|
chrome enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary opensuse
|
extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a …
|
NVD-CWE-Other
|
CVE-2016-1662
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266443
|
8.0 |
HIGH
Network
|
redhat google opensuse
|
enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary chrome opensuse
|
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers…
|
CWE-20
Improper Input Validation
|
CVE-2016-1661
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266444
|
8.8 |
HIGH
Network
|
opensuse redhat google
|
opensuse enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary chrome
|
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service …
|
CWE-20
Improper Input Validation
|
CVE-2016-1660
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266445
|
7.5 |
HIGH
Network
|
cisco
|
ios
|
The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 15.2(2)EB1 on Industrial Ethernet 5000 devices allo…
|
CWE-399
Resource Management Errors
|
CVE-2016-1399
|
2024-11-21 11:46 |
2016-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266446
|
9.8 |
CRITICAL
Network
|
canonical
|
ubuntu-core-launcher
|
The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to ob…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1580
|
2024-11-21 11:46 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266447
|
9.8 |
CRITICAL
Network
|
canonical oxide_project
|
ubuntu_linux oxide
|
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously t…
|
NVD-CWE-Other
|
CVE-2016-1578
|
2024-11-21 11:46 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266448
|
7.1 |
HIGH
Network
|
cisco
|
cloud_network_automation_provisioner
|
SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy721…
|
CWE-89
SQL Injection
|
CVE-2016-1393
|
2024-11-21 11:46 |
2016-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266449
|
6.1 |
MEDIUM
Network
|
websvn debian
|
websvn debian_linux
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1236
|
2024-11-21 11:46 |
2016-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266450
|
8.8 |
HIGH
Network
|
libarchive
|
libarchive
|
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-si…
|
CWE-20
Improper Input Validation
|
CVE-2016-1541
|
2024-11-21 11:46 |
2016-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|