NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20469 | CVE-2016-5130 | content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20470 | CVE-2016-5131 | Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
20471 | CVE-2016-5132 | The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
20472 | CVE-2016-5133 | Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server data stream. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20473 | CVE-2016-5134 | net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, a related issue to CVE-2016-3763. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16060 of 17672, showing 5 records out of 88360 total, starting on record 80296, ending on 80300