VendorsRed Hatenterprise_linux_desktop_supplementary6.0
Vulnerabilities

Red Hat Enterprise Linux Desktop Supplementary 6.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2015-1278
content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.
Published 2015-07-23 · Modified
4.3EPSS 0.018
CVE-2015-1281
core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.
Published 2015-07-23 · Modified
4.3EPSS 0.017
CVE-2015-1287
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp.
Published 2015-07-23 · Modified
4.3EPSS 0.015
CVE-2016-1664
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to spoof the address bar via a crafted web site.
Published 2016-05-14 · Modified
4.3EPSS 0.010
← Prev3 / 3