Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-01-19 | CVE-2016-5199 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Chrome An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted video file. | 8.8 |
2017-01-19 | CVE-2016-5198 | Out-of-bounds Write vulnerability in multiple products V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page. | 8.8 |
2017-01-19 | CVE-2016-5197 | Improper Input Validation vulnerability in Google Chrome The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page. | 8.8 |
2017-01-19 | CVE-2016-5196 | 7PK - Security Features vulnerability in Google Chrome The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page. | 8.8 |
2017-01-18 | CVE-2016-9680 | Information Exposure vulnerability in Citrix Provisioning Services Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors. | 7.5 |
2017-01-18 | CVE-2016-9679 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix Provisioning Services Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer. | 9.8 |
2017-01-18 | CVE-2016-9678 | Use After Free vulnerability in Citrix Provisioning Services Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | 9.8 |
2017-01-18 | CVE-2016-9677 | Information Exposure vulnerability in Citrix Provisioning Services Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors. | 5.3 |
2017-01-18 | CVE-2016-9676 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix Provisioning Services Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | 9.8 |
2017-01-18 | CVE-2016-6497 | 7PK - Security Features vulnerability in Apache Groovy Ldap main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods. | 7.5 |