|
266431
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_computing_system_central_software
|
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1401
|
2024-11-21 11:46 |
2016-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266432
|
7.8 |
HIGH
Local
|
apple
|
itunes
|
Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1742
|
2024-11-21 11:46 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266433
|
8.1 |
HIGH
Network
|
google
|
chrome
|
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/esc…
|
CWE-22
Path Traversal
|
CVE-2016-1671
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266434
|
5.3 |
MEDIUM
Network
|
google opensuse debian
|
chrome opensuse debian_linux
|
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to mak…
|
CWE-362
Race Condition
|
CVE-2016-1670
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266435
|
8.8 |
HIGH
Network
|
debian google opensuse nodejs canonical
|
debian_linux chrome opensuse v8 node.js ubuntu_linux
|
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows rem…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1669
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266436
|
8.8 |
HIGH
Network
|
google opensuse debian
|
chrome opensuse debian_linux
|
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows…
|
CWE-284
Improper Access Control
|
CVE-2016-1668
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266437
|
8.8 |
HIGH
Network
|
opensuse debian google
|
opensuse debian_linux chrome
|
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution duri…
|
CWE-284
Improper Access Control
|
CVE-2016-1667
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266438
|
9.8 |
CRITICAL
Network
|
redhat opensuse google
|
enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary opensuse chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-1666
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266439
|
6.5 |
MEDIUM
Network
|
opensuse redhat google
|
opensuse enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary chrome
|
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sen…
|
CWE-20
Improper Input Validation
|
CVE-2016-1665
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266440
|
4.3 |
MEDIUM
Network
|
google redhat opensuse
|
chrome enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary opensuse
|
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and othe…
|
CWE-254
7PK - Security Features
|
CVE-2016-1664
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|