Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_supplementary CVEs

Beta · best-effort

84 CVEs tagged to redhat / enterprise_linux_server_supplementary22 Critical, 31 High, 30 Medium, 1 Low, 0 Unrated.

CVE-2016-1665

Published May 14, 2016

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote att…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1664

Published May 14, 2016

The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1663

Published May 14, 2016

The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 5…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1662

Published May 14, 2016

extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote a…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2016-1661

Published May 14, 2016

Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which all…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1660

Published May 14, 2016

Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2015-8540

Published Apr 14, 2016

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, a…

CVSS 8.8 · High

CVE-2015-1289

Published Jul 23, 2015

Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVSS 7.5 · High

CVE-2015-1288

Published Jul 23, 2015

The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attacker…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-1287

Published Jul 23, 2015

Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-1286

Published Jul 23, 2015

Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2015-1285

Published Jul 23, 2015

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a trun…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-1282

Published Jul 23, 2015

Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2015-1281

Published Jul 23, 2015

core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to byp…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2015-1280

Published Jul 23, 2015

SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified ot…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2015-1279

Published Jul 23, 2015

Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2015-1278

Published Jul 23, 2015

content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstit…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-1277

Published Jul 23, 2015

Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspeci…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2015-1276

Published Jul 23, 2015

Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2015-1274

Published Jul 23, 2015

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by p…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
17.5
Showing 1-25 of 84 CVEsPage 1 of 4