CVE-2017-5017 – chromium-browser: uninitialised memory access in webm video
https://notcve.org/view.php?id=CVE-2017-5017
27 Jan 2017 — Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video memory, which allowed a remote attacker to possibly extract image fragments on systems with GeForce 8600M graphics chips via a crafted HTML page. Interacciones con el SO en Google Chrome en versiones anteriores a 56.0.2924.76 para Mac de memoria de vídeo insuficientemente borrada, lo que permitió a un atacante remoto posiblemente extraer fragmentos de imagen en sistemas con chips gráficos GeForce 8600M a tra... • http://rhn.redhat.com/errata/RHSA-2017-0206.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-5197
https://notcve.org/view.php?id=CVE-2016-5197
19 Jan 2017 — The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page. El cliente de vista de contenido en Google Chrome anterior a 54.0.2840.85 para Android valida insuficientemente las URLs intencionadas, lo que permitió a un atacante remoto que ha comprometido el proceso de renderización para iniciar actividad arbitraria en e... • http://www.securityfocus.com/bid/94078 • CWE-20: Improper Input Validation •
CVE-2016-5196
https://notcve.org/view.php?id=CVE-2016-5196
19 Jan 2017 — The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page. El cliente renderizado de contenido en Google Chrome anterior a 54.0.2840.85 para Android fuerza insuficientemente la Same Origin Policy entre los archivos descargados, lo que permite a un atacante remoto a... • http://www.securityfocus.com/bid/94078 • CWE-254: 7PK - Security Features •
CVE-2016-5216 – chromium-browser: use after free in pdfium
https://notcve.org/view.php?id=CVE-2016-5216
07 Dec 2016 — A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. Un uso después de liberación de memoria en PDFium en Google Chrome anterior a 55.0.2883.75 para Mac, Windows y Linux y 55.0.2883.84 para Android permitió a un atacante remoto realizar una lectura de la memoria fuera de límites a través de un archivo PDF manipulado. Chromium is an open-source web br... • http://rhn.redhat.com/errata/RHSA-2016-2919.html • CWE-416: Use After Free •
CVE-2016-5225 – chromium-browser: csp bypass in blink
https://notcve.org/view.php?id=CVE-2016-5225
05 Dec 2016 — Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page. Blink en Google Chrome anterior a 55.0.2883.75 para Mac, Windows y Linux y 55.0.2883.84 para Android manejó incorrectamente acciones de formularios, lo que permitió a un atacante remoto eludir la Content Security Policy a través de una página HTML manipulada. Multiple vulnerabilities ... • http://rhn.redhat.com/errata/RHSA-2016-2919.html • CWE-19: Data Processing Errors •
CVE-2016-9650 – chromium-browser: csp referrer disclosure
https://notcve.org/view.php?id=CVE-2016-9650
05 Dec 2016 — Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page. Blink en Google Chrome anterior a 55.0.2883.75 para Mac, Windows y Linux y 55.0.2883.84 para Android maneja iframes incorrectamente, lo que permitió a un atacante remoto eludir una política no referida a través de una página HTML manipulada. Multiple vulnerabilities were discovered in Chromiu... • http://rhn.redhat.com/errata/RHSA-2016-2919.html • CWE-19: Data Processing Errors •
CVE-2016-5221 – chromium-browser: integer overflow in angle
https://notcve.org/view.php?id=CVE-2016-5221
05 Dec 2016 — Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page. Confusión de tipo en libGLESv2 en ANGLE en Google Chrome anterior a 55.0.2883.75 para Mac, Windows y Linux y 55.0.2883.84 para Android posiblemente permitió a un atacante remoto eludir la validación del búfer a través de una página HTML manipulada. Multiple vulnerabilities were discovered i... • http://rhn.redhat.com/errata/RHSA-2016-2919.html • CWE-190: Integer Overflow or Wraparound •
CVE-2016-5209 – chromium-browser: out of bounds write in blink
https://notcve.org/view.php?id=CVE-2016-5209
05 Dec 2016 — Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Mal casting en la manipulación de bitmap en Blink en Google Chrome anterior a 55.0.2883.75 para Mac, Windows y Linux y 55.0.2883.84 para Android permitió a un atacante remoto explotar potencialmente corrupción de memoria a través de una página HTML manipulada. Multiple vulnerabilit... • http://rhn.redhat.com/errata/RHSA-2016-2919.html • CWE-787: Out-of-bounds Write •
CVE-2016-5215 – chromium-browser: use after free in webaudio
https://notcve.org/view.php?id=CVE-2016-5215
05 Dec 2016 — A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. Un uso después de liberación de memoria en webaudio en Google Chrome anterior a 55.0.2883.75 para Mac, Windows y Linux y 55.0.2883.84 para Android permitió a un atacante remoto realizar una lectura de la memoria fuera de límites a través de una página HTML manipulada. Multiple vulnerabilities we... • http://rhn.redhat.com/errata/RHSA-2016-2919.html • CWE-416: Use After Free •
CVE-2016-9651 – Google Chrome - V8 Private Property Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2016-9651
05 Dec 2016 — A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. La falta de una comprobación para detectar si la propiedad de un objeto JS es privado en V8 de Google Chome, en versiones anteriores a la 55.0.2883.75, permitió que un atacante remoto ejecutara código arbitrario en un sandbox mediante una página HTML manipulada. Multiple vulnerabilities were discovered in C... • https://packetstorm.news/files/id/142939 • CWE-94: Improper Control of Generation of Code ('Code Injection') •