NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18048 | CVE-2016-1698 | The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition. | 2 | 4.3 | Medium | 2017-01-19 | 2016-07-29 | View | |
| 18047 | CVE-2016-1697 | The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code. | 2 | 6.8 | Medium | 2017-01-19 | 2016-07-29 | View | |
| 18046 | CVE-2016-1696 | The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-07-29 | View | |
| 18045 | CVE-2016-1695 | Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 18044 | CVE-2016-1694 | browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 2161 of 17672, showing 5 records out of 88360 total, starting on record 10801, ending on 10805