|
266581
|
8.8 |
HIGH
Network
|
opensuse debian google
|
opensuse debian_linux chrome
|
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1627
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266582
|
4.3 |
MEDIUM
Network
|
google opensuse debian
|
chrome opensuse debian_linux
|
The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1626
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266583
|
4.3 |
MEDIUM
Network
|
opensuse google debian
|
opensuse chrome debian_linux
|
The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1625
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266584
|
8.8 |
HIGH
Network
|
opensuse google debian
|
opensuse chrome debian_linux
|
Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overfl…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1624
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266585
|
8.8 |
HIGH
Network
|
debian google opensuse
|
debian_linux chrome opensuse
|
The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1623
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266586
|
8.8 |
HIGH
Network
|
google debian opensuse
|
chrome debian_linux opensuse
|
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1622
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266587
|
8.1 |
HIGH
Network
|
debian mozilla sil fedoraproject
|
debian_linux firefox thunderbird graphite2 fedora
|
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2016-1526
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266588
|
8.6 |
HIGH
Network
|
netgear
|
prosafe_network_management_software_300
|
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the …
|
CWE-22
Path Traversal
|
CVE-2016-1525
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266589
|
9.6 |
CRITICAL
Adjacent
|
netgear
|
prosafe_network_management_software_300
|
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-…
|
NVD-CWE-Other
|
CVE-2016-1524
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266590
|
6.5 |
MEDIUM
Network
|
fedoraproject mozilla sil debian
|
fedora firefox thunderbird graphite2 debian_linux
|
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows…
|
NVD-CWE-Other
|
CVE-2016-1523
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|