CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

Google Chrome Prior to 53.0.2785.89 Multiple Vulnerabilities漏洞银行丨0DAY BANK

2016年9月7日 1285点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

Google Chrome is a web browser for multiple platforms developed by Google.

This Google Chrome update fixes the following vulnerabilities:
CVE-2016-5147: Universal XSS in Blink.
CVE-2016-5148: Universal XSS in Blink.
CVE-2016-5149: Script injection in extensions.
CVE-2016-5150: Use after free in Blink.
CVE-2016-5151: Use after free in PDFium.
CVE-2016-5152: Heap overflow in PDFium.
CVE-2016-5153: Use after destruction in Blink.
CVE-2016-5154: Heap overflow in PDFium.
CVE-2016-5155: Address bar spoofing.
CVE-2016-5156: Use after free in event bindings.
CVE-2016-5157: Heap overflow in PDFium.
CVE-2016-5158: Heap overflow in PDFium.
CVE-2016-5159: Heap overflow in PDFium.
CVE-2016-5161: Type confusion in Blink.
CVE-2016-5162: Extensions web accessible resources bypass.
CVE-2016-5163: Address bar spoofing.
CVE-2016-5164: Universal XSS using DevTools.
CVE-2016-5165: Script injection in DevTools.
CVE-2016-5166: SMB Relay Attack via Save Page As.
CVE-2016-5160: Extensions web accessible resources bypass.
CVE-2016-5167: Various fixes from internal audits, fuzzing and other initiatives.

Affected Versions:
Google Chrome versions prior to 53.0.2785.89 are affected.

漏洞危害

Successful exploitation of these vulnerabilities could allow a remote attacker to bypass certain security restrictions, obtain sensitive information, execute arbitrary code or cause a denial of service condition on the system.

解决方案

Customers are advised to upgrade to Google Chrome 53.0.2785.89 or a later version.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

Google Chrome: Mac OS

Google Chrome: Windows

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me