Search CVE reports


Toggle filters

2281 – 2290 of 3719 results


CVE-2016-5211

Medium priority

Some fixes available 4 of 5

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2016-5210

Medium priority

Some fixes available 4 of 5

Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2016-5206

Medium priority

Some fixes available 4 of 5

The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2016-5203

Medium priority

Some fixes available 4 of 5

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2016-5201

Medium priority

Some fixes available 4 of 5

A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2016-5197

Medium priority
Not affected

The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system...

1 affected package

chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
Show less packages

CVE-2016-5196

Medium priority
Not affected

The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact...

1 affected package

chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
Show less packages

CVE-2014-9911

Medium priority

Some fixes available 2 of 13

Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have...

8 affected packages

android, chromium-browser, firefox, icu, mozjs24...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release Not in release
chromium-browser Not affected Not affected Not in release Not affected
firefox Not affected Not affected Not in release Not affected
icu Not affected Not affected Not affected Not affected
mozjs24 Not in release Not in release Not in release Not in release
thunderbird Not affected Not affected Not in release Not affected
oxide-qt Not in release Not in release Not in release Not in release
r-cran-stringi Not affected Not affected Not affected Not affected
Show all 8 packages Show less packages

CVE-2016-5193

Medium priority
Ignored

Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2016-5191

Medium priority

Some fixes available 4 of 5

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages