Vulnerabilities > Google > Chrome > 52.0.2743.116
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-09-11 | CVE-2016-5150 | Use After Free vulnerability in multiple products WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code that leverages certain side effects. | 8.8 |
2016-09-11 | CVE-2016-5149 | Code Injection vulnerability in multiple products The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection attacks by leveraging script access to a resource that initially has the about:blank URL. | 8.8 |
2016-09-11 | CVE-2016-5148 | Cross-site Scripting vulnerability in Google Chrome Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka "Universal XSS (UXSS)." | 6.1 |
2016-09-11 | CVE-2016-5147 | Cross-site Scripting vulnerability in Google Chrome Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)." | 6.1 |