|
265461
|
8.1 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4834
|
2024-11-21 11:53 |
2016-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265462
|
4.8 |
MEDIUM
Network
|
apache
|
archiva
|
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5005
|
2024-11-21 11:53 |
2016-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265463
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows remote attackers to cause a denial of service or po…
|
CWE-416
Use After Free
|
CVE-2016-5136
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265464
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does no…
|
CWE-200
Information Exposure
|
CVE-2016-5137
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265465
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload re…
|
CWE-20
Improper Input Validation
|
CVE-2016-5135
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265466
|
8.8 |
HIGH
Network
|
google
|
chrome
|
net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows rem…
|
CWE-200
Information Exposure
|
CVE-2016-5134
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265467
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect…
|
CWE-287
Improper Authentication
|
CVE-2016-5133
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265468
|
8.8 |
HIGH
Network
|
google
|
chrome
|
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows rem…
|
CWE-254
7PK - Security Features
|
CVE-2016-5132
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265469
|
8.8 |
HIGH
Network
|
google xmlsoft apple canonical redhat suse opensuse debian
|
chrome libxml2 watchos tvos iphone_os mac_os_x ubuntu_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation linux_enterprise leap ope…
|
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via…
|
CWE-416
Use After Free
|
CVE-2016-5131
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265470
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL dis…
|
CWE-284
Improper Access Control
|
CVE-2016-5130
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|