Unknown · CVSS Not scored
Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.
Published Jan 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to temporarily spoof the contents of the Omnibox (URL bar) via a crafted HTML page containing PDF data.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to read local files via a crafted PDF file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption or DoS via a crafted PDF file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly permitted access to privileged plugins, which allowed a remote attacker to bypass site isolation via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a remote attacker to read local files via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during synchronous event handling, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote attacker to prevent the downloaded file from receiving the Mark of the Web via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android incorrectly applied type rules, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Published Jan 19, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.
Published Jan 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.
Published Jan 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp constraint with a valid certificate.
Published Jan 31, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic.
Published Jan 3, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
Published Jan 20, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
Published Jan 30, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
Published Jan 20, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
Published Jan 20, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
Published Jan 11, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.
Published Jan 11, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
Published Jan 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
Published Jan 11, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
Published Jan 22, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
Published Jan 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.
Published Jan 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Published Jan 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
Published Jan 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.
Published Jan 6, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An exploitable buffer overflow exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a stack based buffer overflow resulting in remote code execution.
Published Jan 6, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.
Published Jan 23, 2017 · Updated Aug 6, 2024