645811 | Crash in mojo::internal::Router::OnConnectionError | - | 2016-12-31 |
648031 | Heap-use-after-free in pp::MacroExpander::expandMacro | - | 2016-12-31 |
647922 | Crash in SuperBlitter::blitH | - | 2016-12-31 |
648935 | Crash in FindBit | - | 2016-12-31 |
649826 | Heap-use-after-free in CPDF_ViewerPreferences::IsDirectionR2L | - | 2016-12-31 |
622271 | Security: Adobe Flash ContextMenu Use After Free | $3,000 | 2016-12-30 |
622634 | Security: use-after-free vulnerability in flash player 22.0.0.192 | $3,000 | 2016-12-30 |
630544 | Security: use-after-free vulnerability in flash player 22.0.0.209 | $3,000 | 2016-12-30 |
630547 | Security: use-after-free vulnerability in Adobe flash player | $3,000 | 2016-12-30 |
640177 | Security: use-after-free vulnerability in flash player latest version | $3,000 | 2016-12-30 |
647791 | Heap-buffer-overflow in gpu::gles2::ShaderTranslator::Translate | - | 2016-12-30 |
648620 | CRASH() writes to a fixed mappable address | - | 2016-12-30 |
649056 | Assertion failed: !object || (object->isBox()) | - | 2016-12-30 |
649095 | Bad-cast to blink::LayoutBox from blink::LayoutInline;blink::LayoutBox::firstChildBox;blink::ThemePainterDefault::setupMenuListArrow | - | 2016-12-30 |
649058 | Use-of-uninitialized-value in blink::BoxPainter::paint | - | 2016-12-30 |
649599 | Crash in blink::ThemePainterDefault::setupMenuListArrow | - | 2016-12-30 |
502871 | Security: adobe flash NetStream.appendBytes ByteArray data Use-After-Free | $3,000 | 2016-12-29 |
646278 | Security: Address Bar URL Spoofing | $500 | 2016-12-29 |
648671 | Bad-cast to webrtc::Module from webrtc::BitrateControllerImpl;webrtc::CongestionController::TimeUntilNextProcess;webrtc::ProcessThreadImpl::Process | - | 2016-12-29 |
647329 | Use-after-poison in fuzz_wasm_section | - | 2016-12-28 |
645540 | Update It2Me host to show confirmation prompt for incoming connections. | - | 2016-12-28 |
648373 | Crash in v8::internal::SloppyArgumentsElementsAccessor<v8::internal::SlowSloppyArgumentsE | - | 2016-12-28 |
645028 | Web accessible resources checks should work with blob: and filesystem: URLs that have chrome-extension:// inner URLs | - | 2016-12-27 |
647612 | Heap-use-after-free in CPDF_RenderStatus::LoadSMask | - | 2016-12-27 |
647893 | Use-of-uninitialized-value in CPDF_DIBSource::TranslateScanline24bpp | - | 2016-12-27 |
647683 | Wrong security state when going back/forward after HTML5 history push | - | 2016-12-27 |
639750 | XSS using Dropjacking | - | 2016-12-26 |
646351 | Crash in v8::internal::SloppyArgumentsElementsAccessor<v8::internal::SlowSloppyArgumentsE | - | 2016-12-26 |
640233 | Use-of-uninitialized-value in SkGradientShaderBase::SkGradientShaderBase | - | 2016-12-25 |
645729 | Use-after-poison in blink::TimerBase::runInternal | $3,500 | 2016-12-25 |
646178 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | - | 2016-12-25 |
647197 | Heap-double-free in v8::internal::wasm::testing::InterpretWasmModule | - | 2016-12-24 |
647110 | Heap-double-free in v8::internal::wasm::testing::InterpretWasmModule | - | 2016-12-24 |
647027 | Heap-use-after-free in v8::internal::wasm::ThreadImpl::Execute | - | 2016-12-24 |
647481 | Use-of-uninitialized-value in SkGradientShaderBase::SkGradientShaderBase | - | 2016-12-24 |
647267 | Crash in blink::TopDocumentRootScrollerController::globalRootScroller | - | 2016-12-24 |
644674 | Attempting free in void v8::internal::LocalArrayBufferTracker::Free< | - | 2016-12-23 |
647269 | Bad-cast to blink::TopDocumentRootScrollerController from blink::RootScrollerController;blink::PaintLayerCompositor::updateClippingOnCompositorLayers;blink::PaintLayerCompositor::updateIfNeeded | - | 2016-12-23 |
646258 | Crash in ReadUnalignedValue<int> | - | 2016-12-23 |
627399 | Use-of-uninitialized-value in CCodec_TiffContext::Decode | - | 2016-12-22 |
621838 | Memcpy-param-overlap in CCodec_ProgressiveDecoder::JpegReadMoreData | - | 2016-12-22 |
645745 | Unable to block cookies | $500 | 2016-12-22 |
646786 | Use-of-uninitialized-value in SkMatrix44::computeTypeMask | - | 2016-12-22 |
646350 | Heap-use-after-free in ash::WmWindowAura::StackChildAbove | - | 2016-12-22 |
641239 | Use-of-uninitialized-value in blink::PointerEventManager::setPointerCapture | - | 2016-12-21 |
638159 | Use-of-uninitialized-value in test_runner::MockWebSpeechRecognizer::PostRunTaskFromQueue | - | 2016-12-21 |
642070 | Use-of-uninitialized-value in update_current_folder_get_info_cb | - | 2016-12-21 |
643939 | Crash in v8::internal::Invoke | - | 2016-12-21 |
645839 | Heap-use-after-free in cc::Scheduler::BeginImplFrameWithDeadline | - | 2016-12-21 |
644733 | Heap-buffer-overflow in blink::LazyLineBreakIterator::nextBreakablePositionIgnoringNBSP | - | 2016-12-21 |
645777 | Use-of-uninitialized-value in base::time_internal::SaturatedSub | - | 2016-12-20 |
645186 | Memcpy-param-overlap in CCodec_ProgressiveDecoder::JpegReadMoreData | - | 2016-12-20 |
645201 | Use-of-uninitialized-value in webrtc::PlayoutDelayLimits::Parse | - | 2016-12-19 |
645770 | Heap-buffer-overflow in void std::vector<aura::Window*, std::allocator<aura::Window*> >::_M_insert_aux<a | - | 2016-12-18 |
644373 | Security - Unexploitable: Integer Overflow in media::mp4::TrackRunIterator::Init leading to arbitrary size OOB read in an arbitrary offset from the buffer. | - | 2016-12-17 |
645034 | Use-of-uninitialized-value in blink::TraceMethodDelegate<blink::PersistentBase<blink::DOMArrayBuffer, | - | 2016-12-17 |
645657 | Use-of-uninitialized-value in base::Pickle::WriteBytes | - | 2016-12-17 |
641995 | value.isFunctionValue() | - | 2016-12-16 |
632709 | Heap-use-after-free in CPDFSDK_Widget::SetAppModified | - | 2016-12-15 |
642803 | Heap-use-after-free in cc::SurfaceManager::UnregisterBeginFrameSource | - | 2016-12-15 |
643726 | Heap-buffer-overflow in safe_browsing::dmg::UDIFBlock::ParseBlockData | - | 2016-12-15 |
643173 | Wrong security state when redirecting to HTTP | $2,000 | 2016-12-15 |
644182 | Heap-buffer-overflow in unibrow::Utf8::Validate | - | 2016-12-15 |
648971 | Chrome OS exploit: c-ares OOB write + dump_vpd_log > symlink | $100,000 | 2016-12-14 |
632848 | !object || (object->isBox()) | - | 2016-12-14 |
637899 | Heap-buffer-overflow in Decode | - | 2016-12-14 |
640998 | Crash in CPDF_Parser::LoadCrossRefV5 | - | 2016-12-14 |
643431 | Crash in v8::internal::Object::SetPropertyInternal | - | 2016-12-14 |
643665 | Crash inside SuperBlitter::blitH | - | 2016-12-14 |
643933 | Crash in SuperBlitter::blitH | - | 2016-12-14 |
643935 | Heap-buffer-overflow in gpu::gles2::Texture::SetLevelInfo | - | 2016-12-14 |
640999 | Heap-use-after-free in base::ObserverListBase<content::RenderThreadObserver>::RemoveObserver | - | 2016-12-13 |
642987 | Heap-buffer-overflow in unibrow::Utf8::Validate | - | 2016-12-13 |
643137 | Heap-use-after-free in blink::TimerBase::getTimerTaskRunner | - | 2016-12-13 |
643970 | Use-of-uninitialized-value in SkUnPreMultiply::PMColorToColor | - | 2016-12-13 |
644003 | Use-of-uninitialized-value in mojo::edk::ChannelPosix::WriteNoLock | - | 2016-12-13 |
624011 | Security: UAF with namespace nodes in XPointer ranges | $3,500 | 2016-12-11 |
638220 | Heap-buffer-overflow in test_runner::BoundsForCharacter | - | 2016-12-10 |
638166 | Heap-use-after-free in content::RenderFrameImpl::NavigateInternal | - | 2016-12-09 |
642867 | Crash in v8::internal::wasm::WasmFullDecoder::AnalyzeLoopAssignment | - | 2016-12-09 |
642639 | <no crash state available> | - | 2016-12-09 |
643071 | Crash in v8::internal::NewSpace::Verify | - | 2016-12-09 |
640576 | Heap-use-after-free in base::WaitableEvent::Signal | - | 2016-12-08 |
642028 | Use-of-uninitialized-value in void WTF::copyToVector<WTF::HashSet<blink::LayoutObject*, WTF::PtrHash<blink::La | - | 2016-12-08 |
497302 | Integer-overflow in sfntly::FontData::Bound | $1,000 | 2016-12-06 |
642063 | Crash in v8::internal::HeapObject::SizeFromMap | - | 2016-12-06 |
641575 | Crash in v8::internal::InstantiateObject | - | 2016-12-05 |
623992 | Use-of-uninitialized-value in unicodetoupper | - | 2016-12-04 |
622197 | Heap-buffer-overflow in u16_u8 | - | 2016-12-03 |
633473 | Use-of-uninitialized-value in Hunspell::spell | - | 2016-12-03 |
638570 | Use-of-uninitialized-value in AffixMgr::compound_check | - | 2016-12-03 |
638562 | Stack-buffer-overflow in SfxEntry::checkword | - | 2016-12-03 |
625915 | Mac: 'Press Esc to exit fullscreen' covered up by permission prompts | - | 2016-12-02 |
638615 | Security: heap-buffer-overflow in ImageBitmap::ImageBitmap | $5,500 | 2016-12-02 |
619368 | Heap-buffer-overflow in content::WriteMemory | - | 2016-12-01 |
631375 | Security: mbspatch: Malform patch file may access heap out of bound | - | 2016-12-01 |
635602 | Heap-use-after-free in content::RenderProcessHostImpl::ConnectionFilterImpl::GetInterface | - | 2016-12-01 |
635879 | Security: Format String Vulnerability in Chrome OS | $1,000 | 2016-12-01 |
638223 | Use-of-uninitialized-value in Break | - | 2016-12-01 |
638742 | Security: Universal XSS using ThreadDebugger::setMonitorEventsCallback | $2,000 | 2016-12-01 |
617124 | Use-of-uninitialized-value in WebRtcSpl_CountLeadingZeros32 | - | 2016-11-30 |
637594 | Security: Universal XSS using DevTools | $2,000 | 2016-11-30 |
639658 | Security: Navigating to "chrome://" URLs via 'about:' protocol | $500 | 2016-11-30 |
637546 | Security: UNKOWN in CFX_Edit_Provider::GetCharWidthW | $1,000 | 2016-11-29 |
639451 | Heap-use-after-free in std::__1::__tree_const_iterator<std::__1::__value_type<CFX_ByteString, CPDF_Obje | - | 2016-11-29 |
639984 | Heap-use-after-free in FORM_DoDocumentAAction | - | 2016-11-29 |
639985 | Use-of-uninitialized-value in shell::internal::InterfaceFactoryBinder<IPC::mojom::ChannelBootstrap>::BindInter | - | 2016-11-29 |
633306 | CSP can be abused to disclose URIs cross-origin | - | 2016-11-25 |
638571 | Heap-use-after-free in blink::DepthOrderedLayoutObjectList::ordered | - | 2016-11-25 |
638928 | !m_deletionHasBegun | - | 2016-11-25 |
628942 | Security: Universal XSS with ScopedPageLoadDeferrer and RemoteFrame | $17,500 | 2016-11-24 |
630654 | Heap-use-after-free in CPDFSDK_Document::KillFocusAnnot | $3,000 | 2016-11-24 |
633474 | Negative-size-param in blink::LayoutGrid::populateExplicitGridAndOrderIterator | - | 2016-11-24 |
638186 | Use-after-poison in blink::SVGLengthContext::convertValueToUserUnits | - | 2016-11-24 |
638192 | Use-after-poison in blink::ElementResolveContext::ElementResolveContext | - | 2016-11-24 |
638226 | Use-of-uninitialized-value in v8::internal::PointerUpdateJobTraits< | - | 2016-11-24 |
619381 | Crash in GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture | - | 2016-11-23 |
633385 | CUPS domain socket should only be openable by user chonos | - | 2016-11-23 |
635848 | Security: Crash in CPDF_Dictionary::GetObjectBy | $1,000 | 2016-11-23 |
638185 | Bad-cast to const blink::LayoutBox from blink::LayoutSVGResourcePattern;blink::PaintInvalidationState::updateForNormalChildren;blink::PaintInvalidationState::updateForChildren | - | 2016-11-23 |
638219 | Bad-cast to blink::LayoutBox from blink::LayoutSVGEllipse;blink::LayoutObject::positionForPoint;blink::LayoutBox::clippingRect | - | 2016-11-23 |
622033 | Heap-buffer-overflow in sctp_send_deferred_reset_response | - | 2016-11-22 |
630870 | Security: Universal XSS by intercepting a UA shadow tree | $7,500 | 2016-11-22 |
636268 | Security: heap-buffer-overflow in SkColorSpace | $3,500 | 2016-11-22 |
634557 | Security: Blob file entries aren't checked against security policy | - | 2016-11-22 |
628999 | Crash in blink::Geolocation::onGeolocationPermissionUpdated | - | 2016-11-21 |
635577 | Crash in mojo::AssociatedBinding<blink::mojom::blink::BroadcastChannelClient>::RunConnect | - | 2016-11-19 |
637320 | Security: Unchecked .end() iterator dereference in VTVideoDecodeAccelerator::ReusePictureBuffer | - | 2016-11-19 |
625404 | Security: use-after-free in AttachFilteredEvent on event_bindings.cc | $3,000 | 2016-11-18 |
628920 | Security: Address bar spoofing on iOS | - | 2016-11-18 |
625575 | Security: bypassing CORS by XHR + MemoryCache + ServiceWorker | - | 2016-11-18 |
633687 | Security: Full browser crash when trying to open missing 'downloaded' resource file. | - | 2016-11-18 |
626893 | Security: Arbitrary memory write in v8::internal::GlobalHandles::IterateNewSpaceWeakUnmodifiedRoots() | $3,000 | 2016-11-17 |
628542 | Heap-buffer-overflow in unibrow::Utf8::Validate | - | 2016-11-17 |
631368 | Crash in blink::getPropertyNameString | - | 2016-11-17 |
634954 | Security: Address bar spoofing with itunes page on iOS | - | 2016-11-17 |
636194 | Crash in void SkLinearGradient::LinearGradientContext::shade4_dx_clamp<false, false> | - | 2016-11-17 |
635571 | Crash in blink::EventTarget::fireEventListeners | - | 2016-11-17 |
622420 | Security: Type confusion in StylePropertySerializer::getCustomPropertyText. | - | 2016-11-16 |
632124 | Global-buffer-overflow in silk_NLSF2A | - | 2016-11-16 |
635574 | Use-after-poison in blink::CrossThreadPersistentRegion::shouldTracePersistentNode | $3,500 | 2016-11-16 |
600352 | Security: Cross-Protocol Theft from non-HTTP services via DNS rebinding + HTTP/0.9 | - | 2016-11-15 |
611955 | //components/filesystem/public/interfaces/*.mojom files need security review | - | 2016-11-15 |
618037 | Security: Devtools old remote frontend allows running privileged scripts via overwriting localStorage settings | $1,000 | 2016-11-15 |
633472 | Use-of-uninitialized-value in segment | - | 2016-11-15 |
632849 | Heap-buffer-overflow in SkA8_Blitter::blitH | - | 2016-11-13 |
628890 | Security: heap-buffer-overflow in opj_tcd_code_block_dec_allocate | $3,500 | 2016-11-12 |
628304 | Security: heap-buffer-overflow in opj_v4dwt_interleave_h | $3,500 | 2016-11-12 |
634238 | Security: Adobe Flash Button.blendMode setter uninitialized stack variable | - | 2016-11-12 |
635045 | Use-of-uninitialized-value in blink::ImagePattern::isLocalMatrixChanged | - | 2016-11-12 |
619429 | Security: Able to bypass permission prompt on keypress | - | 2016-11-11 |
624514 | Heap-buffer-overflow in CWeightTable::Calc | $3,500 | 2016-11-11 |
634114 | Heap-use-after-free in blink::LayoutFieldset::adjustInnerStyle | - | 2016-11-11 |
634394 | Security: UAF in PDFium's TimerProc() | - | 2016-11-11 |
627355 | Crash in _platform_memmove$VARIANT$Nehalem | - | 2016-11-10 |
632965 | Security: OOB read with CallSite and wasm | - | 2016-11-10 |
633585 | Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer | - | 2016-11-10 |
633471 | Use-of-uninitialized-value in GrPipeline::CreateAt | - | 2016-11-08 |
633486 | Tracking bug for internal fixes: Chrome M52, release 1 | - | 2016-11-08 |
479961 | Apply wpa_supplicant P2P vulnerability fixes | - | 2016-11-07 |
632634 | Security: Universal XSS with static methods and ScriptState::forHolderObject | $7,500 | 2016-11-07 |
610644 | Heap-buffer-overflow in ps_table_add | $1,500 | 2016-11-06 |
632850 | Crash in CPDFSDK_InterForm::GetWidget | - | 2016-11-06 |
632851 | Heap-use-after-free in CJS_Timer::KillJSTimer | - | 2016-11-06 |
632860 | Heap-buffer-overflow in copy | - | 2016-11-05 |
616429 | Security: Saving WebPage with file: resources access SMB resources | $1,000 | 2016-11-04 |
631052 | Use-after-poison in blink::CompositorAnimationPlayer::NotifyAnimationStarted | $3,500 | 2016-11-04 |
631320 | Heap-use-after-free in content::WebRTCEventLogHost::PeerConnectionRemoved | - | 2016-11-04 |
629919 | Security: heap-buffer-overflow in opj_tcd_update_tile_data | $5,000 | 2016-11-03 |
631050 | Crash in v8::internal::JSObject::UpdateAllocationSite | - | 2016-11-03 |
573131 | Security: some extension bindings incorrectly injected into about:blank frames | $7,500 | 2016-11-02 |
627414 | Crash in MaskSuperBlitter::blitH | - | 2016-11-02 |
630377 | Heap-use-after-free in ProfileIOData::FromResourceContext | - | 2016-11-02 |
629455 | Heap-buffer-overflow in SuperBlitter::blitH | - | 2016-11-02 |
631319 | Container-overflow in gpu::gles2::GLES2DecoderImpl::DoScheduleCALayerFilterEffectsCHROMIUM | - | 2016-11-02 |
631752 | Tracking bug for internal fixes: Chrome OS 52.0.2743.85 (Platform version: 8350.60.0) | - | 2016-11-02 |
628992 | Heap-use-after-free in SuperBlitter::blitH | - | 2016-11-01 |
627454 | Use-of-uninitialized-value in blink::PointerEventManager::setPointerCapture | - | 2016-11-01 |
630736 | Crash in segment | - | 2016-11-01 |
630369 | Use-of-uninitialized-value in GrShape::attemptToSimplifyPath | - | 2016-10-31 |
630749 | Heap-use-after-free in mojo::BindingSet<network_hints::mojom::NetworkHints>::AddBinding | - | 2016-10-31 |
623195 | Use-of-uninitialized-value in base::Pickle::WriteData | - | 2016-10-29 |
630649 | Stack-buffer-overflow in SkDCubic::searchRoots | - | 2016-10-29 |
399951 | Security: Cross-origin information leak via ECMAScript harmony proxies | $1,000 | 2016-10-28 |
614647 | Use-of-uninitialized-value in get_advance | - | 2016-10-28 |
621362 | Security: Universal XSS with Flash calling into JavaScript inside Node::removedFrom | $7,500 | 2016-10-28 |
629962 | Use-of-uninitialized-value in segment | - | 2016-10-28 |
628117 | Heap-use-after-free in blink::PaintController::commitNewDisplayItems | $3,500 | 2016-10-28 |
630378 | Use-of-uninitialized-value in SkDPoint::approximatelyEqual | - | 2016-10-28 |
624213 | Security: Address bar RTL character spoofing on Mac | - | 2016-10-27 |
624214 | Security: Address bar RTL character spoofing on iOS | - | 2016-10-27 |
629795 | Use-of-uninitialized-value in gpu::gles2::GLES2DecoderImpl::HandleGetBufferParameteriv | - | 2016-10-27 |
626186 | Crash in SkOpAngle::setSpans | - | 2016-10-26 |
627401 | Crash in SkOpCoincidence::mark | - | 2016-10-26 |
628995 | Use-of-uninitialized-value in CPWL_List_Notify::IOnInvalidateRect | - | 2016-10-26 |
629452 | Crash in segment | - | 2016-10-26 |
629454 | Use-of-uninitialized-value in containsCoincidence | - | 2016-10-26 |
616623 | Use-of-uninitialized-value in walk_convex_edges | - | 2016-10-25 |
629004 | Use-of-uninitialized-value in gpu::gles2::GLES2DecoderImpl::DoDrawBuffersEXT | - | 2016-10-25 |
629008 | Use-of-uninitialized-value in gpu::gles2::GLES2Implementation::WaitSyncTokenCHROMIUM | - | 2016-10-25 |
629435 | Crash in v8::internal::Invoke | - | 2016-10-25 |
623319 | URL Spoof due to subframes and NavigationEntry corruption | $2,000 | 2016-10-21 |
627436 | Negative-size-param in content::MediaStreamDispatcherHost::OnCancelDeviceChangeNotifications | - | 2016-10-21 |
627756 | Security: SEGV on unknown address in toCSSValuePair | $3,000 | 2016-10-21 |
627443 | Use-of-uninitialized-value in gpu::gles2::GLES2Implementation::BufferDataHelper | - | 2016-10-21 |
628113 | Use-of-uninitialized-value in blink::LayoutObject::setPreferredLogicalWidthsDirty | - | 2016-10-21 |
628130 | Stack-buffer-overflow in saturated_add | - | 2016-10-21 |
626790 | Crash in blink::ComputeFloatOffsetForFloatLayoutAdapter<2>::heightRemaining | - | 2016-10-20 |
627354 | Negative-size-param in content::WebRTCEventLogHost::PeerConnectionRemoved | - | 2016-10-20 |
627434 | Use-of-uninitialized-value in sk_sse41::blit_row_s32a_opaque | - | 2016-10-20 |
627447 | Use-of-uninitialized-value in ProfileChooserView::ButtonPressed | - | 2016-10-20 |
627457 | Use-after-poison in content::WebMessagePortChannelImpl::OnMessage | $3,500 | 2016-10-20 |
611957 | //components/leveldb/public/interfaces/leveldb.mojom needs a security review | - | 2016-10-19 |
618295 | Security: [PDFium]AddressSanitizer: negative-size-param | - | 2016-10-19 |
623168 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-19 |
626182 | Heap-use-after-free in blink::PaintController::commitNewDisplayItems | - | 2016-10-19 |
623365 | Heap Buffer Overflow in iframe URL Parse | - | 2016-10-17 |
579934 | Chromium allows to open popup window from Flash object without user gesture or blocking | $1,000 | 2016-10-15 |
610986 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-15 |
617648 | Heap-use-after-free in content::FilteringNetworkManager::Initialize | - | 2016-10-15 |
626562 | Crash in v8::internal::HandleBase::IsDereferenceAllowed | - | 2016-10-15 |
626792 | Heap-use-after-free in GURL::GURL | - | 2016-10-15 |
617105 | Security: use-after-free vulnerability in flash player | $3,000 | 2016-10-14 |
623072 | Use-of-uninitialized-value in containsCoincidence | - | 2016-10-14 |
625541 | Security: heap-buffer-overflow in opj_tcd_init_tile | $3,000 | 2016-10-14 |
625823 | Security: SEGV in blink::DOMWindowV8Internal::blurMethodCallback | $1,000 | 2016-10-14 |
625945 | Security: browser history sniffing via HSTS + CSP (bypass previous fix) | $1,000 | 2016-10-14 |
613949 | Extension install crashes browser at onDownloadProgress and onInstallStageChanged | $500 | 2016-10-13 |
625903 | Security: heap-use-after-free in blink::LayoutBox::pixelSnappedOffsetHeight | $2,000 | 2016-10-13 |
624818 | Use-of-uninitialized-value in gpu::gles2::GLES2Implementation::BufferDataHelper | - | 2016-10-13 |
623378 | Security: UAF related to XPointer range-to function | $3,500 | 2016-10-12 |
625752 | Crash in v8::internal::LocalArrayBufferTracker::Free<1> | - | 2016-10-12 |
625393 | Security: Heap-use-after-free in ScriptInjector | $1,000 | 2016-10-11 |
616907 | Security: Universal XSS using a ScopedPageLoadDeferrer bypass | $8,000 | 2016-10-10 |
619379 | CharacterData::setData() should handle first-letter correctly | - | 2016-10-06 |
620952 | i < m_len | - | 2016-10-06 |
624713 | Security: Calling from WASM to JS should not pass the global object | - | 2016-10-06 |
291417 | Security: <webview>/App Request Contexts may not be so isolated | - | 2016-10-05 |
561978 | Vulnerability reported in media-libs/libpng | - | 2016-10-05 |
609382 | Security: Use after free of task_struct in Mali Midgard driver. | - | 2016-10-05 |
612050 | Heap-use-after-free in views::Widget::OnNativeWidgetDestroying | - | 2016-10-05 |
609680 | Chrome For Android Address Bar Spoofing Issue Due To Mishandling Of RTL Characters | $3,000 | 2016-10-05 |
617882 | Crash in v8::internal::PointerUpdateJobTraits< | - | 2016-10-05 |
618333 | Security: Parameter sanitization failure in DevTools leads to privileged script execution | $2,000 | 2016-10-05 |
619414 | Security: Devtools has Insuffient sanitization of remoteBase parameter | $2,000 | 2016-10-05 |
620981 | Crash in _platform_bzero$VARIANT$Merom | - | 2016-10-05 |
621843 | Heap-buffer-overflow in float blink::ShapeResultSpacing::computeSpacing<unsigned short> | - | 2016-10-05 |
623985 | Use-after-poison in blink::PersistentBase<blink::WorkerWebSocketChannel::Bridge, | $3,500 | 2016-10-05 |
623996 | Use-of-uninitialized-value in blink::LineBoxList::deleteLineBoxes | - | 2016-10-05 |
617084 | Crash in v8::internal::HandleBase::IsDereferenceAllowed | - | 2016-10-04 |
619377 | Bad-cast to blink::WebGLObject from invalid vptr;blink::WebGLProgram::deleteObjectImpl;blink::WebGLSharedObject::detachContextGroup | - | 2016-10-04 |
621095 | SIGSEGV, RIP = 0x0 | - | 2016-10-04 |
118642 | Heap-use-after-free in v8::internal::JSObject::GetElementWithInterceptor | $1,000 | 2016-10-02 |
118662 | Regression(r109014): Heap-use-after-free in WebCore::InlineTextBox::isLineBreak | $500 | 2016-10-02 |
118593 | Heap-use-after-free in WebCore::SVGStyledElement::buildPendingResourcesIfNeeded | $1,000 | 2016-10-02 |
118490 | Heap-use-after-free in WebCore::RenderObject::containingBlock | $1,000 | 2016-10-02 |
118467 | open.call(other_window) circumvents check in other_window.open() | - | 2016-10-02 |
118633 | Security: Frame sniffing is not fixed | - | 2016-10-02 |
118414 | Heap use after free on chrome_content_browser_client.cc with webrtc | $1,000 | 2016-10-02 |
118374 | Long autofilled value causes render issue | - | 2016-10-02 |
118273 | ZDI-CAN-1528: Webkit HTMLMedia Element beforeLoad Remote Code Execution Vulnerability | - | 2016-10-02 |
118227 | Security: cross-origin iframes can be resized from within in M18 | - | 2016-10-02 |
118018 | Heap-buffer-overflow in S32_opaque_D32_nofilter_DXDY | - | 2016-10-02 |
118317 | Popup blocker bypass triggering mouse event on tag with rel=noreferrer | - | 2016-10-02 |
118185 | Heap-use-after-free in WebCore::V8HTMLBodyElement::wrapSlow | - | 2016-10-02 |
117890 | Use-after-free in CrashGenerationServer | - | 2016-10-02 |
117912 | Heap-buffer-overflow in memcmp | - | 2016-10-02 |
117794 | [LangFuzz] Crash on heap with invalid read through GetPropertyWithCallback | $500 | 2016-10-02 |
117736 | No permission prompt when loading unpacked extension with NPAPI plugin | - | 2016-10-02 |
117728 | Heap-use-after-free in WebCore::InlineBox::root | $1,000 | 2016-10-02 |
117724 | Event handlers firing during Text::splitText trigger use-after-free. | - | 2016-10-02 |
118009 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 0ul>::append<unsigned short> | - | 2016-10-02 |
117889 | Dangerous download warnings are suppressed for a larger class of downloads than are handled by SafeBrowsing | - | 2016-10-02 |
117698 | Heap-use-after-free in WebCore::RenderLayer::addChild | $1,000 | 2016-10-02 |
117696 | Heap-use-after-free in WebCore::RenderBlock::addPositionedFloats | - | 2016-10-02 |
117674 | Heap-use-after-free in WebCore::GraphicsContext3D::getExtensions | - | 2016-10-02 |
117672 | Uptake angle security fix | - | 2016-10-02 |
117656 | Pwnium bug: GPU memory corruption | - | 2016-10-02 |
117627 | Security: IPC Channel does not validate the listener. | - | 2016-10-02 |
117620 | Pwnium bug: Prerendering issues with NACL | $60,000 | 2016-10-02 |
117715 | LoadExtension binding in chrome://extensions/ is too permissive | - | 2016-10-02 |
117583 | Iframe hijacking from Pwnium | - | 2016-10-02 |
117588 | Security: Memory Corruption in MaskSuperBlitter | $1,000 | 2016-10-02 |
117545 | ICU lang buffer overflow | - | 2016-10-02 |
117471 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | $1,000 | 2016-10-02 |
117446 | App popup user gesture exemption should be based on process type, not just extent | - | 2016-10-02 |
117418 | Security: Don't grant WebUI bindings to a process shared with normal views | - | 2016-10-02 |
117417 | Security: Don't let a normal web renderer navigate to a privileged URL | - | 2016-10-02 |
117413 | Heap-use-after-free in WebCore::RenderScrollbar::getScrollbarPseudoStyle | - | 2016-10-02 |
117409 | Chrome: Crash Report - Stack Signature: v8::internal::MarkCompactCollector::RecordS... | - | 2016-10-02 |
117400 | Uptake fixes on weak node iteration patterns | - | 2016-10-02 |
117511 | Heap-use-after-free in WTF::equal | - | 2016-10-02 |
117335 | Occasional heap-use-after-free in non-virtual thunk to AudioDevice::OnStateChanged | $500 | 2016-10-02 |
117341 | Heap-use-after-free in MessageLoop::AddToIncomingQueue | $1,000 | 2016-10-02 |
117230 | Part 2 of Pwnium Bug | - | 2016-10-02 |
117226 | Part 1 of Pwnium Bug: UXSS | $60,000 | 2016-10-02 |
117150 | REGRESSION(wk109285): Heap-use-after-free in WebCore::Document::nodeChildrenWillBeRemoved | $1,000 | 2016-10-02 |
117110 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
116994 | Heap-use-after-free in chrome::ChromeContentBrowserClient::RequestMediaAccessPermission | - | 2016-10-02 |
116967 | Heap-buffer-overflow in WebCore::SVGUseElement::instanceForShadowTreeElement | - | 2016-10-02 |
116927 | Heap-buffer-overflow in av_freep | $1,000 | 2016-10-02 |
116806 | Heap-use-after-free in WebCore::RenderInline::continuationBefore | - | 2016-10-02 |
116746 | Heap-use-after-free in WebCore::RenderBlock::splitBlocks | $1,000 | 2016-10-02 |
116637 | Renderer process crash when doing WebGL canvas to 2D canvas drawImage() | - | 2016-10-02 |
116524 | Security: Off-by-one in OTS resulting in arbitrary code execution | - | 2016-10-02 |
116461 | Heap-use-after-free in WebCore::CSSCrossfadeValue::~CSSCrossfadeValue | $1,000 | 2016-10-02 |
116405 | Mitigate stale layout root bugs | - | 2016-10-02 |
116398 | Security: SSL proxy seems to not care about the cert | - | 2016-10-02 |
116474 | Merge SVG use fix to stable | - | 2016-10-02 |
121926 | Heap-buffer-overflow in WebCore::FEConvolveMatrix::platformApplySoftware | - | 2016-10-02 |
121937 | glGetProgramInfoLog regression in ANGLE | - | 2016-10-02 |
121734 | Heap-use-after-free in WebCore::V8AbstractEventListener::~V8AbstractEventListener | - | 2016-10-02 |
121726 | Sandbox IPC length checking race | - | 2016-10-02 |
121703 | Crash in NSMutableRLEArray replaceObjectsInRange:withObject:length with long URL | - | 2016-10-02 |
121692 | Heap-use-after-free in WebCore::SelectorChecker::checkOneSelector | - | 2016-10-02 |
121645 | Heap-use-after-free in WebCore::RenderBlock::removeFloatingObject | - | 2016-10-02 |
121899 | Security: use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer() | $1,000 | 2016-10-02 |
121736 | Heap-use-after-free in WebCore::EventDispatcher::dispatchEvent | - | 2016-10-02 |
121347 | Heap-buffer-overflow in WebCore::RenderBlock::LineBreaker::nextLineBreak | $500 | 2016-10-02 |
121524 | Use after free with reflections and composited layers | - | 2016-10-02 |
121206 | Heap-buffer-overflow in WebCore::HTMLSelectElement::setRecalcListItems | - | 2016-10-02 |
121128 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::append<unsigned short> | - | 2016-10-02 |
120977 | Crash in texSubImage2D on Mozilla's WebGL performance regression tests | - | 2016-10-02 |
121269 | invalid cast in WebCore::toHTMLElement / WebCore::HTMLFieldSetElement::disabledAttributeChanged | - | 2016-10-02 |
121223 | Heap-use-after-free in WebCore::WorkerThreadableWebSocketChannel::Bridge::mainThreadCreateWebSocketChannel | $500 | 2016-10-02 |
121407 | [LangFuzz] Invalid write in v8::internal::ElementsAccessorBase<...>::CopyElements | $1,000 | 2016-10-02 |
120648 | UNKNOWN in SkARGB32_Blitter::blitV | $500 | 2016-10-02 |
120457 | Global-buffer-overflow in WebCore::InlineTextBox::isLineBreak | - | 2016-10-02 |
120711 | Heap-use-after-free in WebCore::Element::recalcStyle | $1,000 | 2016-10-02 |
120944 | Use-after-free due to issues in counter layout. | $1,000 | 2016-10-02 |
120912 | Heap-use-after-free in WebCore::RenderText::removeTextBox | $1,000 | 2016-10-02 |
120320 | Flash Broker Bypass 0x2B (CVE-2012-0724) | - | 2016-10-02 |
120318 | Flash Broker Bypass 0x2D (CVE-2012-0725) | - | 2016-10-02 |
120222 | Heap-use-after-free in WebCore::RenderTableSection::paintCell | $1,000 | 2016-10-02 |
120205 | Security: <svg:use> elements in the parser can create elements not marked as created by the parser | - | 2016-10-02 |
120404 | Heap-buffer-overflow in WebCore::Font::codePath | - | 2016-10-02 |
120037 | Heap-use-after-free in WebCore::ContainerNode::resumePostAttachCallbacks | $1,000 | 2016-10-02 |
120007 | Heap-use-after-free in WebCore::WorkerEventQueue::close | - | 2016-10-02 |
120403 | Heap-use-after-free in WebCore::ContainerNode::insertBefore | - | 2016-10-02 |
120189 | Heap-use-after-free in WebCore::V8RecursionScope::didLeaveScriptContext | - | 2016-10-02 |
119926 | Use after free in v8::internal::IncrementalMarking::Step | $1,000 | 2016-10-02 |
119501 | Heap-use-after-free in WebCore::SVGStyledElement::buildPendingResourcesIfNeeded | $1,000 | 2016-10-02 |
119429 | UNKNOWN in v8::Message::GetScriptResourceName | $500 | 2016-10-02 |
120006 | Heap-use-after-free in WebCore::RenderBlock::finishDelayUpdateScrollInfo | - | 2016-10-02 |
119525 | Heap-use-after-free in WebCore::ApplyStyleCommand::applyInlineStyleToNodeRange | $1,000 | 2016-10-02 |
119281 | Heap-use-after-free in WebCore::GenericEventQueue::~GenericEventQueue | $500 | 2016-10-02 |
119230 | Heap-use-after-free in WebCore::RenderBlock::splitBlocks | - | 2016-10-02 |
119150 | Sandboxed processes should not be able to open other sandboxed processes | - | 2016-10-02 |
119084 | Heap-use-after-free in utext_setNativeIndex_46 | - | 2016-10-02 |
118970 | GPU process crash below DoDrawArrays (Nvidia) | $500 | 2016-10-02 |
119305 | Heap-use-after-free in WebCore::Node::~Node | $1,000 | 2016-10-02 |
119250 | GPU, Plugin, and NaCl processes have PROCESS_DUP_HANDLE permission on renderer processes | - | 2016-10-02 |
118803 | Heap-use-after-free in WebCore::SVGTextLayoutAttributesBuilder::fillCharacterDataMap | - | 2016-10-02 |
118784 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::insert<unsigned short> | - | 2016-10-02 |
118853 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
118664 | Security: Swapped out URL must be a unique origin | - | 2016-10-02 |
118721 | Extensions resources can be fetched across incognito | - | 2016-10-02 |
116162 | Heap-buffer-overflow in wk_png_inflate | - | 2016-10-02 |
116128 | Content scripts should never be run in the webstore isolate | - | 2016-10-02 |
116093 | Heap-buffer-overflow in WebCore::SVGDocumentExtensions::removeAnimationElementFromTarget | $1,000 | 2016-10-02 |
116069 | WebCore::MediaStreamListInternal::itemCallback | $500 | 2016-10-02 |
116224 | Heap-use-after-free in WebCore::FrameLoader::urlSelected | - | 2016-10-02 |
115998 | Heap-use-after-free in WebCore::RenderMenuList::addChild | - | 2016-10-02 |
115862 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
115756 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
115754 | Heap-use-after-free in WebCore::RenderLayer::addChild | $1,000 | 2016-10-02 |
115695 | Heap-buffer-overflow in WebCore::StaticNodeList::itemWithName | $1,000 | 2016-10-02 |
115681 | Heap-use-after-free in WebCore::RenderBox::enclosingFloatPaintingLayer | $1,000 | 2016-10-02 |
115680 | Heap-use-after-free in WebCore::RenderListItem::updateMarkerLocation | - | 2016-10-02 |
115807 | Heap-use-after-free in WebCore::RenderMenuList::addChild | - | 2016-10-02 |
116027 | Heap-buffer-overflow in WebCore::InlineFlowBox::addToLine | - | 2016-10-02 |
115159 | Security: Setting innerText allows DOMSubtreeModified listeners to cause crashes | - | 2016-10-02 |
115028 | Bad cast in splitAnonymousBlocksAroundChild (part 3) | $1,000 | 2016-10-02 |
115003 | Heap-use-after-free in WebCore::RenderObject::previousInPreOrder | - | 2016-10-02 |
115299 | Use-after-free in AudioDeviceThread::Callback::InitializeOnAudioThread | $500 | 2016-10-02 |
115471 | Heap-buffer-overflow in SkAlphaRuns::add | $1,000 | 2016-10-02 |
114924 | Bad cast in splitAnonymousBlocksAroundChild | $1,000 | 2016-10-02 |
114911 | Heap-buffer-overflow in WebCore::Element::setAttribute | - | 2016-10-02 |
114858 | Heap-use-after-free in WebCore::RenderTableSection::willBeDestroyed | - | 2016-10-02 |
114960 | Heap-use-after-free in WebCore::SVGTextLayoutAttributesBuilder::fillCharacterDataMap | - | 2016-10-02 |
114219 | Heap-use-after-free in WebCore::RenderTableSection::nodeAtPoint | $1,000 | 2016-10-02 |
114152 | Heap-use-after-free in WebCore::InspectorStyleSheet::deleteRule | - | 2016-10-02 |
114144 | Crash by clicking the time field of maps.google.com | - | 2016-10-02 |
114068 | Heap-use-after-free in WebCore::HTMLElement::isPresentationAttribute | $1,000 | 2016-10-02 |
114056 | Heap-buffer-overflow in WebCore::previousBoundary | $500 | 2016-10-02 |
114054 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 0ul>::append<unsigned short> | $500 | 2016-10-02 |
113924 | [LangFuzz] Crash at v8::internal::HashTable<...>::FindEntry with invalid read | $1,000 | 2016-10-02 |
114342 | Stack-buffer-overflow at strcpy | $1,000 | 2016-10-02 |
113837 | Heap-use-after-free in WebCore::Document::unregisterForPageCacheSuspensionCallbacks | $1,000 | 2016-10-02 |
113800 | Heap-use-after-free in WebCore::RenderBlock::computeOverflow | - | 2016-10-02 |
113902 | Heap-use-after-free in WebCore::InlineBox::root | $1,000 | 2016-10-02 |
113799 | Heap-use-after-free in WebCore::RenderTable::layout | - | 2016-10-02 |
113801 | Heap-use-after-free in WebCore::RenderBlock::outlineStyleForRepaint | - | 2016-10-02 |
113733 | Security: Flash deployed via component updater runs outside the sandbox | - | 2016-10-02 |
113755 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
113707 | Heap-use-after-free in WebCore::RenderQuote::placeQuote | $1,000 | 2016-10-02 |
113690 | Heap-use-after-free in WebCore::RenderButton::removeChild | - | 2016-10-02 |
113567 | Heap-use-after-free in WebCore::RenderRegion::setRegionBoxesRegionStyle | - | 2016-10-02 |
113562 | Heap-use-after-free in WebCore::NavigationScheduler::schedule | - | 2016-10-02 |
113730 | Integer wrap in CSSParser::quoteCSSString() can cause a buffer overflow | - | 2016-10-02 |
113497 | Heap-use-after-free in WebCore::InlineFlowBox::computeUnderAnnotationAdjustment | $1,000 | 2016-10-02 |
113496 | Links in settings page (like learn more, google dashboard) are opened in the webui renderer process | - | 2016-10-02 |
113439 | Bad casts due to issues in splitAnonymousBlocksAroundChild | $1,000 | 2016-10-02 |
113415 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
113258 | Bad cast in WebCore::RenderBlock::createLineBoxes | $1,000 | 2016-10-02 |
113178 | Adding a ShadowRoot to a SELECT element causes crashes | - | 2016-10-02 |
113174 | Attaching a ShadowRoot to a VIDEO element causes heap-use-after-free | - | 2016-10-02 |
113160 | Security: Tracking bug for WK77971 - Replaces the [CheckNodeSecurity] IDL attribute | - | 2016-10-02 |
113119 | Security: Report bad translation link uses http:// | - | 2016-10-02 |
112976 | Heap-use-after-free in vorbis_decode_frame | - | 2016-10-02 |
112961 | TCP and UDP IPCs should not be exposed to arbitrary renderers | - | 2016-10-02 |
112983 | Browser crash with FTP video source | - | 2016-10-02 |
125462 | Security: libxml2 1-byte heap-buffer-overflow in xmlXPtrEvalXPtrPart | $1,500 | 2016-10-02 |
125436 | Heap-use-after-free in WebCore::HTMLFormControlElement::disabled | - | 2016-10-02 |
125249 | Heap-buffer-overflow in seg_to | - | 2016-10-02 |
125225 | Domui process can be ptraced from a compromised renderer leading to sandbox escape, take 2 | - | 2016-10-02 |
125159 | Chrome chrashes when pressing back button on a page that is still downloading a big gif image | $1,337 | 2016-10-02 |
125151 | Heap-use-after-free in WebCore::Node::compareDocumentPosition | - | 2016-10-02 |
125010 | Stealing AutoFill data with window.getSelection() before users actually select form contents | - | 2016-10-02 |
125494 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::processEndTag | - | 2016-10-02 |
125374 | Heap-use-after-free in WebCore::RenderSVGContainer::paint | $1,000 | 2016-10-02 |
124992 | Heap-use-after-free in WebCore::swapInNodePreservingAttributesAndChildren | - | 2016-10-02 |
124923 | Heap-use-after-free in WebCore::parseToDoubleForNumberType | - | 2016-10-02 |
124919 | Heap-use-after-free in WebCore::RenderBlock::addOverflowFromFloats | - | 2016-10-02 |
124895 | Heap-use-after-free in WebCore::ScriptController::executeIfJavaScriptURL | - | 2016-10-02 |
124893 | Heap-buffer-overflow in WebCore::HTMLOptionElement::selected | - | 2016-10-02 |
124870 | Heap-use-after-free in WebCore::InsertParagraphSeparatorCommand::doApply | - | 2016-10-02 |
124868 | Heap-use-after-free in WebCore::RenderObject* WebCore::bidiNextShared<WebCore::BidiResolver<WebCore::InlineIterator, WebCor | - | 2016-10-02 |
124836 | NSS should reject DH public values equal to one | - | 2016-10-02 |
125000 | Heap-buffer-overflow in WTF::VectorMover<false, WebCore::Attribute>::move | - | 2016-10-02 |
124924 | Heap-buffer-overflow in WebCore::XPath::sortBlock | - | 2016-10-02 |
124652 | Heap-buffer-overflow in SkDashPathEffect::SkDashPathEffect | - | 2016-10-02 |
124625 | Chrome: Crash Report - Stack Signature: WebCore::npObjectNamedGetter<WebCore::V8HTM... | - | 2016-10-02 |
124617 | Heap-buffer-overflow in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
124669 | Heap-use-after-free in WebCore::SVGLength::value | - | 2016-10-02 |
124530 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
124594 | UNKNOWN in v8::internal::MarkCompactCollector::PrepareThreadForCodeFlushing | $500 | 2016-10-02 |
124479 | Use after free in PDF with corrupt CID font encoding name | - | 2016-10-02 |
124356 | Heap-use-after-free in WebCore::GraphicsContext::restore | $1,000 | 2016-10-02 |
124263 | OOB read with PDF in cell sorting | - | 2016-10-02 |
124228 | Security: Component updater parses unauthenticated XML with libxml in the browser process | - | 2016-10-02 |
124216 | Security: MSVR:159 - Google Chrome NPAPI Plugin Insecure Loading Elevation of Privilege Vulnerability | - | 2016-10-02 |
124191 | OOB read in PDF when parsing / processing text | - | 2016-10-02 |
124190 | OOB read, off-by-one in PDF predictor code with specific decode parameters | - | 2016-10-02 |
124184 | OOB read with 1bpp image and ICC profile | - | 2016-10-02 |
124183 | OOB read in PDF fax codec | - | 2016-10-02 |
124389 | Heap-use-after-free in WebCore::TargetListener::clear | - | 2016-10-02 |
124182 | Out of bounds write in PDF with sample function with lots of inputs | - | 2016-10-02 |
124179 | PDF crash under ASAN with character maps | - | 2016-10-02 |
123929 | Out-of-bounds read in PDF with undersized "O" key and revision 3 crypto | - | 2016-10-02 |
123858 | Use-after-free in WebPagePopupImpl instance | - | 2016-10-02 |
123735 | OOB reads in PDF AES support due to buffer mismanagement | - | 2016-10-02 |
123733 | Out-of-bounds reads with bad parameters to PDF "sampled function" function | - | 2016-10-02 |
123709 | Breakpad ClientInfo::PopulateCustomInfo() integer wrap leads to heap overflow | - | 2016-10-02 |
123656 | OOB read in PDF whilst scanning for "startxref" | - | 2016-10-02 |
123631 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | - | 2016-10-02 |
123544 | Heap-use-after-free in WebCore::CachedResource::checkNotify | - | 2016-10-02 |
123530 | Heap-use-after-free in AutocompleteMatch::AutocompleteMatch | - | 2016-10-02 |
123484 | Global-buffer-overflow in WebCore::InlineTextBox::isLineBreak | - | 2016-10-02 |
123481 | Security: ERROR: AddressSanitizer heap-buffer-overflow on address 0x7fde15ff9890 at pc 0x7fde364c5034 | $1,000 | 2016-10-02 |
123105 | Heap-buffer-overflow in Color32_SSE2 | - | 2016-10-02 |
123054 | Security: renderer can grant itself read permissions to arbitrary files | - | 2016-10-02 |
123029 | OOB write in SkARGB32_Black_Blitter::blitAntiH -> sk_memset32_SSE2 | $1,000 | 2016-10-02 |
123012 | Chrome: Crash Report - Stack Signature:WebCore::V8BindingPerContextData::constructorForType(WebCore::WrapperTypeInfo *) | - | 2016-10-02 |
122925 | Security: Autofill info can be captured by innocuous social engineering | $1,000 | 2016-10-02 |
122865 | Heap-use-after-free in SkCanvas::internalDrawBitmapRect | - | 2016-10-02 |
122760 | Heap-use-after-free in WebCore::RenderTable::computePreferredLogicalWidths | - | 2016-10-02 |
122692 | UNKNOWN in /lib/libc-2.11.1.so+Unknown | - | 2016-10-02 |
122681 | [LangFuzz] CHECK(fixed_size + height_in_bytes == input_frame_size) failed or crash with invalid read | $500 | 2016-10-02 |
122654 | Chrome: Crash Report: SocketStreamDispatcherHost::CancelSSLRequest | - | 2016-10-02 |
122586 | Global-buffer-overflow in HB_TibetanShape | - | 2016-10-02 |
122585 | Security: stack-buffer-overflow in WebCore::GlyphPage::fill with surrogate characters | $500 | 2016-10-02 |
122573 | Heap-use-after-free in WebCore::CachedRawResource::didAddClient | - | 2016-10-02 |
122854 | Security: Potential (racy) use after free error in DownloadResourceHandler::OnResponseCompletedInternal | - | 2016-10-02 |
122503 | Heap-buffer-overflow in erode | - | 2016-10-02 |
122337 | [LangFuzz] Crash on heap with invalid write (32 bit only). | $1,000 | 2016-10-02 |
122208 | GCing a node observed by a WebKitMutationObserver can cause an invalid HashSet iterator | - | 2016-10-02 |
122029 | Heap-buffer-overflow in WebCore::InlineFlowBox::addToLine | - | 2016-10-02 |
122014 | Heap-use-after-free in WorkerEventQueue::close | - | 2016-10-02 |
121968 | Heap-use-after-free in WebCore::GraphicsLayer::willBeDestroyed | - | 2016-10-02 |
122562 | Heap-use-after-free in ModuleSystem::LazyFieldGetter | $1,000 | 2016-10-02 |
112847 | Bad cast in addChildToAnonymousColumnBlocks | $1,000 | 2016-10-02 |
112833 | Heap-use-after-free in webkit_media::BufferedResourceLoader::Start | $1,000 | 2016-10-02 |
112822 | Security: Heap-buffer-overflow in png_decompress_chunk | $1,337 | 2016-10-02 |
112814 | Safe Browsing client doesn't always check for MAC field in response | - | 2016-10-02 |
112775 | Heap-use-after-free in WebCore::Node::traverseNextNode | - | 2016-10-02 |
112764 | Heap-use-after-free in RendererAccessibility::SendPendingAccessibilityNotifications | - | 2016-10-02 |
112738 | Security: User Interface - infobar confusion, spamming, and spoofing | - | 2016-10-02 |
112735 | Bad cast in FormSubmission::create | - | 2016-10-02 |
112694 | Heap-use-after-free in WebCore::Node::normalize | - | 2016-10-02 |
112670 | avcodec_53!ff_h264_get_profile - crash | $500 | 2016-10-02 |
112451 | X509UserCertResourceHandler::OnResponseCompleted crash | - | 2016-10-02 |
112443 | [Mac] Regular SSL certificate incorrectly displayed with EV color badge | - | 2016-10-02 |
112542 | Heap-use-after-free in WebCore::TextIterator::rangeFromLocationAndLength | - | 2016-10-02 |
112411 | Heap-use-after-free in WebCore::SVGUseElement::expandSymbolElementsInShadowTree | $1,000 | 2016-10-02 |
112391 | Heap-use-after-free in ExtensionHost | - | 2016-10-02 |
112339 | Security: chrome allows TDR looping leading to win7 OS crash through page refresh html tag + WebGL | - | 2016-10-02 |
112325 | Security: Copy-paste preserves <embed> tags containing active content | - | 2016-10-02 |
112317 | Heap-buffer-overflow in WebCore::Font::codePath | $500 | 2016-10-02 |
112259 | Heap-use-after-free in WebCore::EventTarget::dispatchEvent | $500 | 2016-10-02 |
112236 | Security: Chrome translation script downloaded over HTTP | - | 2016-10-02 |
112212 | Heap-use-after-free in WebCore::ContainerNode::appendChild | $2,000 | 2016-10-02 |
112151 | Heap-use-after-free in WebCore::RenderRegion::setRegionBoxesRegionStyle | $1,000 | 2016-10-02 |
112093 | Heap-use-after-free in WebCore::Node::dispatchSubtreeModifiedEvent | - | 2016-10-02 |
112055 | Heap-buffer-overflow in WebCore::CSSParser::lex | - | 2016-10-02 |
111779 | Heap-use-after-free in WebCore::SubframeLoader::loadSubframe | $1,000 | 2016-10-02 |
111748 | Heap-use-after-free in WebCore::SVGElement::removedFromDocument | $1,000 | 2016-10-02 |
111656 | Security: Accessibility bad cast | - | 2016-10-02 |
111575 | Security: NaCl dynamic code modification allows direct calls inside existing super instructions. | - | 2016-10-02 |
111491 | AddressSanitizer reports a heap-use-after-free in icu_46::RuleBasedBreakIterator::handleNext in DownloadTest.CrxLargeTheme (browser_tests) on Chrome OS | - | 2016-10-02 |
111088 | Heap-use-after-free in WebCore::FrameLoader::checkTimerFired | - | 2016-10-02 |
111467 | Heap-buffer-overflow in WebCore::SVGSVGElement::currentViewBoxRect | $1,000 | 2016-10-02 |
110849 | Heap-buffer-overflow in matroska_parse_block | - | 2016-10-02 |
110764 | Heap-use-after-free in WebCore::DocumentLoader::detachFromFrame | $1,000 | 2016-10-02 |
110723 | Heap-use-after-free in WebCore::RenderSVGResourceContainer::markAllClientsForInvalidation | - | 2016-10-02 |
111342 | Heap-use-after-free in AudioDevice::FireRenderCallback | - | 2016-10-02 |
110559 | Heap-buffer-overflow in GPU ShaderTranslator | - | 2016-10-02 |
110374 | Heap-use-after-free in WebCore::EventHandler::mouseMoved | $1,000 | 2016-10-02 |
110360 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | - | 2016-10-02 |
110277 | Heap-buffer-overflow in xsltCompilePatternInternal | $500 | 2016-10-02 |
110172 | Heap-buffer-overflow in SkAlphaRuns::add | $1,000 | 2016-10-02 |
110545 | Security: AssociatedURLLoader exposes non-whitelisted response headers when loading with access control (CORS) | - | 2016-10-02 |
110076 | Heap-use-after-free in WebCore::CompositeEditCommand::ensureComposition | - | 2016-10-02 |
109743 | Heap-use-after-free in WebCore::CSSStyleSelector::matchRulesForList | $1,000 | 2016-10-02 |
109717 | Security: crash when viewing a certificate without issuer signature | - | 2016-10-02 |
109716 | Heap-use-after-free in xsltParseGlobalVariable | $1,000 | 2016-10-02 |
109691 | Security: Losing user-set pin data on HSTS header receipt | - | 2016-10-02 |
110112 | Heap-use-after-free in WebCore::FrameView::forceLayoutParentViewIfNeeded | $1,000 | 2016-10-02 |
109912 | Security: read sandbox escape: NaCl validator for x86-64 allow REP string instructions to have out-of-bound source addresses | - | 2016-10-02 |
109623 | Chrome: Crash Report - Stack Signature: WebKit::WebMediaPlayerClientImpl::loadInter... | - | 2016-10-02 |
109574 | Potential XSS attack with [0x8E][0xE3] in EUC-JP page | $500 | 2016-10-02 |
109556 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::HTMLTreeBuilder | $1,000 | 2016-10-02 |
109411 | Regression: Crash in WebCore::DynamicSubtreeNodeList::length() | - | 2016-10-02 |
109245 | Security: Chrome Drag Spoofing | - | 2016-10-02 |
109664 | safe_browsing::SignatureUtil::CheckSignature() - crash | - | 2016-10-02 |
109094 | Possible wild read in internal PDF-reader | - | 2016-10-02 |
108958 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
129158 | Heap-use-after-free in WebCore::AccessibilityObject::getAttribute | - | 2016-10-02 |
129191 | UNKNOWN in WebCore::HTMLDocumentParser::prepareToStopParsing | $1,000 | 2016-10-02 |
128971 | Heap-use-after-free in WebCore::InlineBox::deleteLine | - | 2016-10-02 |
128711 | Run-in UAF crashes relating to generated content and inline line box tree not clearing. | - | 2016-10-02 |
128704 | Crash when opening and closing chrome://chrome | - | 2016-10-02 |
128688 | Heap-buffer-overflow in gpu::gles2::GLES2Implementation::TexSubImage2DImpl | - | 2016-10-02 |
128800 | Use after free in WebCore::SVGTextLayoutAttributesBuilder::fillCharacterDataMap | - | 2016-10-02 |
128597 | RenderViewImpl's shared_popup_counter_ isn't incremented properly | - | 2016-10-02 |
128498 | Heap-buffer-overflow in WebCore::CSSSelector::specificityForOneSelector | - | 2016-10-02 |
128497 | CachedImage does not clear the ImageObserver pointer when dropping its Image ref | - | 2016-10-02 |
128458 | Security: NTP Promo data is downloaded via HTTP, but then rendered on the NTP | - | 2016-10-02 |
128665 | Heap-use-after-free in WebCore::Node::isInShadowTree | - | 2016-10-02 |
128342 | Heap-buffer-overflow in WebCore::SVGUseElement::instanceForShadowTreeElement | - | 2016-10-02 |
128336 | Heap-buffer-overflow in WebCore::SubframeLoader::createJavaAppletWidget | - | 2016-10-02 |
128256 | tabs permission exploit on the Chrome RSS Extension | - | 2016-10-02 |
128204 | Assertion failure (toRenderBox() called on a RenderInline) beneath RenderBlock::blockBeforeWithinSelectionRoot() | - | 2016-10-02 |
128178 | Heap-use-after-free in fileapi::FileSystemOperation::DidGetUsageAndQuotaAndRunTask | $3,133 | 2016-10-02 |
128163 | Heap-buffer-overflow in GIFImageReader::read | - | 2016-10-02 |
128159 | Heap-use-after-free in WTF::HashMap<int, WTF::RefPtr<WebCore::CalculationValue>, WTF::IntHash<unsigned int>, WTF::HashTrait | - | 2016-10-02 |
128157 | Heap-use-after-free in WebCore::HTMLFormControlElement::disabled | - | 2016-10-02 |
128151 | Heap-use-after-free in WebKit::MainThreadFileSystemCallbacks::didSucceed | - | 2016-10-02 |
128146 | UNKNOWN in v8::internal::DescriptorArray::Set | - | 2016-10-02 |
128018 | [LangFuzz] Crash in v8::internal::ShortCircuitConsString with invalid read | $1,000 | 2016-10-02 |
127889 | Use after free in WebCore::Font::characterRangeCodePath / WebCore::Font::codePath | - | 2016-10-02 |
127764 | Heap-use-after-free in WebCore::RenderBlock::xPositionForFloatIncludingMargin | - | 2016-10-02 |
127701 | Heap-use-after-free in WebCore::RenderObject::repaint | - | 2016-10-02 |
127648 | Out of bounds read in WebCore::Region::Shape::compareShapes | - | 2016-10-02 |
127624 | Security: pepper plugins - protect plugin's data files from other plugins and the renderer itself. | - | 2016-10-02 |
127525 | Dragging a file into a web renderer exposes the file: scheme | $500 | 2016-10-02 |
127522 | Security: Chrome Allows "Carpet Bomb" from File Download | - | 2016-10-02 |
127727 | Heap-use-after-free in WebCore::ContextDestructionObserver::contextDestroyed | - | 2016-10-02 |
127449 | PPAPI processes hold privileged process handles | - | 2016-10-02 |
127418 | Heap-use-after-free in WebCore::SVGTextLayoutEngine::layoutTextOnLineOrPath | $1,000 | 2016-10-02 |
127417 | Security: Arbitrary memory read in libxslt | $500 | 2016-10-02 |
127371 | Heap-use-after-free in WebCore::AXObjectCache::postNotification | - | 2016-10-02 |
127368 | Heap-use-after-free in WebCore::SVGAnimatedLengthAnimator::resetAnimValToBaseVal | - | 2016-10-02 |
127367 | Heap-use-after-free in WebCore::ApplyStyleCommand::joinChildTextNodes | - | 2016-10-02 |
127366 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::performTrivialReplace | - | 2016-10-02 |
127424 | Heap-use-after-free in WebKit::WebPagePopupImpl::closePopup | $1,000 | 2016-10-02 |
127234 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::FloatRect>::commitChange | - | 2016-10-02 |
126723 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
126652 | Heap-buffer-overflow in bool WebCore::Region::Shape::compareShapes<WebCore::Region::Shape::CompareIntersectsOperation> | - | 2016-10-02 |
126475 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
126414 | [LangFuzz] Crash on heap with invalid read from random address (32 bit) | $500 | 2016-10-02 |
126406 | Heap-use-after-free in WebCore::RenderBlock::addChildIgnoringAnonymousColumnBlocks | - | 2016-10-02 |
126343 | OOB write in PDF character code mapping | - | 2016-10-02 |
126337 | Stack buffer overflow in character range parsing | - | 2016-10-02 |
126296 | Security: Browser crash document.createEvent("MouseEvents").initMouseEvent in background tab | $1,000 | 2016-10-02 |
125730 | Heap-use-after-free in WebCore::Document::nodeChildrenWillBeRemoved | - | 2016-10-02 |
126105 | Global-buffer-overflow in RgnOper::addSpan | - | 2016-10-02 |
126074 | Heap-use-after-free in WebCore::SpellChecker::didCheckSucceeded | - | 2016-10-02 |
126048 | Heap-use-after-free in SpeechRecognitionManagerImpl::DispatchEvent | $1,000 | 2016-10-02 |
126040 | Heap-use-after-free in WebCore::ContainerNode::insertBefore | - | 2016-10-02 |
126015 | Heap-use-after-free in WebCore::HTMLFormControlElement::disabled | - | 2016-10-02 |
125921 | Heap-buffer-overflow in WebCore::FontCache::releaseFontData | - | 2016-10-02 |
125919 | Heap-buffer-overflow in WebCore::SVGAnimatedPointListAnimator::calculateAnimatedValue | $500 | 2016-10-02 |
125821 | The Linux setuid sandbox has becomre (even more) insanely complex | - | 2016-10-02 |
126075 | Stack-buffer-overflow in SuggestMgr::forgotchar_utf | - | 2016-10-02 |
125563 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
125557 | Heap-use-after-free in WebCore::AudioParam::disconnect | - | 2016-10-02 |
125555 | Heap-use-after-free in WTF::HashMap<int, WTF::RefPtr<WebCore::CalculationValue>, WTF::IntHash<unsigned int>, WTF::HashTrait | - | 2016-10-02 |
125529 | Heap-use-after-free in WebCore::HTMLLinkElement::setCSSStyleSheet | - | 2016-10-02 |
125515 | [LangFuzz] Crash on heap with invalid write to random address | $1,000 | 2016-10-02 |
108918 | Heap-use-after-free in WebCore::RenderTableSection::rowLogicalHeightChanged | - | 2016-10-02 |
108901 | Heap-buffer-overflow in compute_pos_tan | $500 | 2016-10-02 |
108894 | Heap-use-after-free in WebCore::HTMLCollection::length | - | 2016-10-02 |
108871 | IndexedDB with autoincrement fails on object put and crashes chrome | $1,000 | 2016-10-02 |
108605 | Use of uninitialized value in SkAlphaRuns::Break | $1,000 | 2016-10-02 |
108798 | Heap-use-after-free in WebCore::(anonymous namespace)::AllowFileSystemMainThreadBridge::signalCompleted | - | 2016-10-02 |
108695 | Heap-use-after-free in WebKit::WebFrameImpl::viewImpl | $1,000 | 2016-10-02 |
108648 | Security: Malicious extension could avoid being blacklisted via extension blacklist | - | 2016-10-02 |
108476 | Heap-buffer-overflow in WebCore::Font::codePath | $500 | 2016-10-02 |
108544 | Heap-use-after-free in SubresourceLoader::didFinishLoading | $1,000 | 2016-10-02 |
108579 | Heap-buffer-overflow in void WTF::Vector<WTF::RefPtr<WebCore::TextTrack>, 0ul>::insert<WTF::RefPtr<WebCore::TextTrack> > | - | 2016-10-02 |
108461 | Heap-use-after-free in WebCore::HTMLInputElement::copyNonAttributeProperties | - | 2016-10-02 |
108416 | Global-buffer-overflow in render_line | $500 | 2016-10-02 |
108071 | Browser process heap-use-after-free with indexeddb cursors | $3,133 | 2016-10-02 |
108037 | Heap-buffer-overflow in WebCore::SVGLength::valueAsString | $1,000 | 2016-10-02 |
108006 | Stack-buffer-overflow in HB_MyanmarShape | - | 2016-10-02 |
108267 | Heap-use-after-free in WebCore::RenderBlock::selectionGaps | - | 2016-10-02 |
108207 | Heap-use-after-free in WebCore::RenderTable::borderBefore | $1,000 | 2016-10-02 |
107758 | Heap-use-after-free in WebCore::RenderRegion::offsetFromLogicalTopOfFirstPage | $1,000 | 2016-10-02 |
107565 | Security: dragging a file URL between two http-spawned windows goes remote->local | - | 2016-10-02 |
107873 | Heap-use-after-free in WebCore::DatabaseTracker::interruptAllDatabasesForContext | - | 2016-10-02 |
107616 | UXSS in v8 bindings npCreateV8ScriptObject() | - | 2016-10-02 |
107939 | Heap-buffer-overflow in WebCore::RenderBlock::layoutRunsAndFloatsInRange | - | 2016-10-02 |
107258 | Freed m_renderer used in InlineBox::deleteLine | - | 2016-10-02 |
107244 | Heap-use-after-free in DatabaseObserver | $1,000 | 2016-10-02 |
107376 | Memory corruption crash in ExtensionPrefs::MigrateAppIndex. | - | 2016-10-02 |
107128 | Heap-buffer-overflow in xmlStringLenDecodeEntities | $4,000 | 2016-10-02 |
107277 | Heap-use-after-free in WebCore::RenderTextFragment::willBeDestroyed | - | 2016-10-02 |
107182 | Heap use after free with malware blocking page | $3,133 | 2016-10-02 |
106672 | Security: Crash in requestAnimationFrame when removing a frame | $1,000 | 2016-10-02 |
106671 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
106577 | Heap-buffer-overflow in SkAAClipBlitter::blitAntiH | $500 | 2016-10-02 |
107032 | Sad tab when visiting https://code.google.com and --no-displaying-insecure-content | - | 2016-10-02 |
106441 | Stack-buffer-overflow in _canonicalize | $1,000 | 2016-10-02 |
106419 | Global-buffer-overflow in SkFileDescriptorStream::read | - | 2016-10-02 |
106413 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
106340 | Heap-use-after-free in WebCore::RenderTable::outerBorderAfter | $3,000 | 2016-10-02 |
106336 | Heap-use-after-free in WebCore::CounterNode::insertAfter | $500 | 2016-10-02 |
106334 | Security: Popupblocker is ignored, downloads are invisible | - | 2016-10-02 |
106484 | Heap-use-after-free in WebCore::RenderObject::childAt | $1,000 | 2016-10-02 |
106309 | Heap-buffer-overflow in WebCore::InlineFlowBox::addToLine (regions issue) | - | 2016-10-02 |
106165 | Heap-buffer-overflow in safe_browsing protocol parser | - | 2016-10-02 |
105867 | Use after free in V8HTMLElementWrapperFactory.cpp | $1,000 | 2016-10-02 |
105803 | PDF missing integer validation for Flate / LZW / Fax prediction codes and other parameters | - | 2016-10-02 |
106200 | Heap-use-after-free in WebCore::InlineBox::deleteLine | $500 | 2016-10-02 |
106316 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::processEndTag | - | 2016-10-02 |
105482 | Security: CSP connect-src and script-src not enforced on workers | - | 2016-10-02 |
105459 | Use-after frees and bad casts with -webkit-column-span | $2,000 | 2016-10-02 |
105714 | Nasty looking INVALID_POINTER_READ in internal PDF-reader | $500 | 2016-10-02 |
134123 | Heap-use-after-free in WebCore::VisibleSelection::rootEditableElement | - | 2016-10-02 |
105162 | Stack-buffer-overflow in base::files::(anonymous namespace)::InotifyReaderTask::Run | - | 2016-10-02 |
134305 | Heap-use-after-free in WebCore::RenderObject::absoluteBoundingBoxRect | - | 2016-10-02 |
133725 | Security: public chromium site is leaking internal Google DNS names | - | 2016-10-02 |
134088 | Use-after-free: LabelsNodeList isn't updated properly after its owner node is adopted into a new document | - | 2016-10-02 |
133892 | Heap-use-after-free in WebCore::RenderListItem::updateMarkerLocation | - | 2016-10-02 |
133288 | Heap-buffer-overflow in WebCore::CSPSourceList::parseSource | - | 2016-10-02 |
133571 | Heap-use-after-free in SkARGB32_Black_Blitter::blitAntiH | $1,000 | 2016-10-02 |
133418 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
134101 | Security: webRequest API allows extensions to XSS chrome.google.com and gain access to webstorePrivate API | $2,000 | 2016-10-02 |
133214 | UNKNOWN in WebCore::RenderTableSection::addCell | $1,000 | 2016-10-02 |
133196 | Heap-use-after-free in WebCore::RenderInline::willBeDestroyed | - | 2016-10-02 |
132806 | ChromeContentBrowserClient::AllowSocketAPI using allowed_socket_origins_ without scheme check | - | 2016-10-02 |
132779 | Security: WebM heap-buffer-overflow in matroskadec.c:matroska_parse_block() | $1,000 | 2016-10-02 |
132699 | Update Java version metadata for Jun 2012 CPU | - | 2016-10-02 |
132690 | Heap-use-after-free in WebCore::RenderSVGModelObject::checkIntersection | - | 2016-10-02 |
132890 | Crash when using Web Audio + media element with no audio or when user navigates | - | 2016-10-02 |
131969 | Heap-use-after-free in WebCore::AccessibilityObject::getAttribute | - | 2016-10-02 |
132396 | Heap-use-after-free in WebCore::RenderBlock::layoutRunsAndFloats | - | 2016-10-02 |
132398 | Global-buffer-overflow in D_Clear_BitmapXferProc | - | 2016-10-02 |
132203 | UAF in ValueStoreFrontend::Backend::Get | - | 2016-10-02 |
132019 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
132270 | Global-buffer-overflow in WebCore::mediaControlElementType | - | 2016-10-02 |
131968 | Heap-use-after-free in WebCore::AccessibilityTable::isDataTable | - | 2016-10-02 |
132241 | Heap-use-after-free in WebCore::DocumentThreadableLoader::cancel | - | 2016-10-02 |
131934 | Heap-use-after-free in WTF::Vector<WebCore::Attribute, 0ul>::~Vector | - | 2016-10-02 |
131348 | Security: Use-after-free in safe_browseing::DownloadProtectionService found by Valgrind | - | 2016-10-02 |
131347 | heap-use-after-free in DictionaryValue while closing chrome, requires extension. | - | 2016-10-02 |
131087 | UAF due to Document::removePendingSheet re-entering JavaScript during Document cleanup | - | 2016-10-02 |
130927 | Heap-use-after-free in WebCore::CompositeEditCommand::breakOutOfEmptyListItem | - | 2016-10-02 |
130824 | Security: Linux crash report generation code reads past the end of an unterminated string buffer. | - | 2016-10-02 |
130802 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 0ul>::append<unsigned short> | - | 2016-10-02 |
130743 | Chromium is no more asking you for permissions to run WMP plugin via the Infobar. Is it intentional? | - | 2016-10-02 |
130723 | Use after free after setting -webkit-line-clamp to none | - | 2016-10-02 |
130722 | Heap-use-after-free in WebCore::InsertParagraphSeparatorCommand::doApply | - | 2016-10-02 |
130595 | Heap-use-after-free in WebCore::RenderBlock::layoutBlockChildren | $1,000 | 2016-10-02 |
130356 | Heap-use-after-free in WebCore::SVGDocumentExtensions::removeAllElementReferencesForTarget | $1,000 | 2016-10-02 |
130276 | Chrome attempts to load metro_driver.dll when Metro is not supported | - | 2016-10-02 |
130241 | [crash] WebCore::RenderStyle::fontMetrics(void)+0xa | - | 2016-10-02 |
130240 | Heap-buffer-overflow WRITE in read_markers third_party/libjpeg_turbo/jdmarker | $1,000 | 2016-10-02 |
130237 | Heap-use-after-free in WebCore::RenderObject::arenaDelete | - | 2016-10-02 |
130235 | Heap-use-after-free in WebCore::HTMLElement::adjustDirectionalityIfNeededAfterChildrenChanged | - | 2016-10-02 |
130369 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | $1,000 | 2016-10-02 |
129826 | Chrome_Mac: Zombie <DownloadItemController: 0x1f1e6fd0> received -handleReveal: (via -performSelector:withObject:) | - | 2016-10-02 |
129947 | Heap-use-after-free in WebCore::RenderObject::setStyle | $1,000 | 2016-10-02 |
129942 | UNKNOWN in v8_i18n::IntlNumberFormat::JSInternalFormat | $1,000 | 2016-10-02 |
129936 | Heap-use-after-free in WebCore::InlineTextBox::nodeAtPoint | - | 2016-10-02 |
129930 | Security: libxml2 growBuffer integer overflow on 64-bit machines | $3,000 | 2016-10-02 |
129898 | Heap-use-after-free in WebCore::CounterNode::lastDescendant | $1,000 | 2016-10-02 |
129890 | Heap-use-after-free in WebCore::cancelAll | - | 2016-10-02 |
129951 | UNKNOWN in v8::Function::Call | $1,000 | 2016-10-02 |
129394 | Heap-use-after-free in WebCore::AccessibilityTable::isDataTable | - | 2016-10-02 |
129569 | Heap-use-after-free in WebCore::RenderLayer::updateCompositingLayersAfterScroll | - | 2016-10-02 |
129396 | Heap-buffer-overflow in WebCore::RenderTable::colElement | - | 2016-10-02 |
129357 | Heap-buffer-overflow in WebCore::RenderProgress::isDeterminate | - | 2016-10-02 |
129301 | Heap-use-after-free in WebCore::AXObjectCache::postPlatformNotification | - | 2016-10-02 |
129299 | Run-in UAFs part 2 | - | 2016-10-02 |
129360 | Heap-use-after-free in WebCore::InlineFlowBox::removeChild | - | 2016-10-02 |
105143 | Cross-origin drag-and-drop prevention ineffective | - | 2016-10-02 |
105157 | Heap-use-after-free in WebCore::InlineFlowBox::removeChild | - | 2016-10-02 |
105133 | Heap-use-after-free in WebCore::RenderObject::isDescendantOf | - | 2016-10-02 |
105012 | Global-buffer-overflow in WebCore::RenderFlexibleBox::mainAxisBorderAndPaddingExtentForChild | - | 2016-10-02 |
104935 | Security: HSTS "cookies" do not obey expected policy. | - | 2016-10-02 |
104863 | Heap-use-after-free in WebCore::SubresourceLoader::didFail | $1,000 | 2016-10-02 |
104859 | Heap-use-after-free in WebCore::InlineFlowBox::computeOverAnnotationAdjustment | $1,000 | 2016-10-02 |
104617 | Heap-use-after-free in WebCore::CSSImageGeneratorValue::addClient | - | 2016-10-02 |
104529 | PDF-reader tab-crash with editable crash address. | $2,000 | 2016-10-02 |
104959 | Nasty looking crash on internal pdf-reader | $500 | 2016-10-02 |
104461 | Security: chrome://workers/ crash | - | 2016-10-02 |
104325 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
104315 | Heap-use-after-free WebCore::RenderObject::container | - | 2016-10-02 |
104272 | Security: Directory traversal in extension docs | - | 2016-10-02 |
104266 | Heap-use-after-free in WebCore::nextBreakablePosition | - | 2016-10-02 |
104466 | Schema check on navigations to chrome/file schemas should be avoided | - | 2016-10-02 |
104317 | Stale RenderObject in RenderBlock::addChildIgnoringAnonymousColumnBlocks() | - | 2016-10-02 |
104056 | Crash with PDF at bad IP | $1,000 | 2016-10-02 |
104223 | Security: MHTML can be used to steal cookies | - | 2016-10-02 |
103867 | Security: chrome.test.resetQuota extension API exposed to all extensions | - | 2016-10-02 |
103750 | minor self-inflicted xss on chrome://tracking2 | - | 2016-10-02 |
103738 | Security: out of bounds array access in WebCore::RenderTableSection::rowLogicalHeightChanged | - | 2016-10-02 |
104011 | v8_i18n::BCP47ToICUFormat() - crash | $1,000 | 2016-10-02 |
104151 | Bad cast in WebCore::RenderThemeMac::paintMediaToggleClosedCaptionsButton | - | 2016-10-02 |
103921 | Use-after-free in DOM Range | $1,000 | 2016-10-02 |
103239 | Security: INVALID_POINTER_READ/WRITE_EXPLOITABLE_chrome!SkRgnBuilder::blitH | $1,000 | 2016-10-02 |
103259 | [LangFuzz] Crash at v8::internal::WriteQuoteJsonString with invalid write | $1,000 | 2016-10-02 |
102810 | Security: buffer overflow in link prefetching | $1,000 | 2016-10-02 |
103630 | Security: iFrame SandBox Unique Origin not enforced in extensions | - | 2016-10-02 |
103126 | Heap-use-after-free in WebCore::RenderTextFragment::styleDidChange | - | 2016-10-02 |
103244 | Pinning checks aren't enforced in the case of a minor error. | - | 2016-10-02 |
103058 | Security: missing xslt import causes crash w/preloading | $1,000 | 2016-10-02 |
102037 | Security: Use after free in CSSStyleDeclarationInternal::parentRuleAttrGetter | - | 2016-10-02 |
101900 | Security: bug rendering web pages with flash content | - | 2016-10-02 |
101835 | Exit full screen button crashs browser | - | 2016-10-02 |
101779 | OOB read with corrupt PDF; possible stability issue too | - | 2016-10-02 |
101624 | Security: buffer overrun leading to heap corruption in ANGLE shader translator | - | 2016-10-02 |
102242 | ZDI-CAN-1416: WebKit ContentEditable swapInNode Use-After-Free Remote Code Execution Vulnerability | - | 2016-10-02 |
101901 | Security:scrolling web with flash content rendering bug | - | 2016-10-02 |
102628 | Security: Adobe regions use-after-free with multiple region css thingies | $1,000 | 2016-10-02 |
102461 | Failure to infobar JRE7 | - | 2016-10-02 |
102359 | Use-after-free in SVG renderer | $1,000 | 2016-10-02 |
101446 | Use after free in TextTrack::~TextTrack | - | 2016-10-02 |
101235 | Security: Location bar spoofing when using replaceState in unload event handler | - | 2016-10-02 |
101205 | Security: marketplace | - | 2016-10-02 |
101172 | Seeking on webm 1080p video causes crash | - | 2016-10-02 |
101580 | Heap-use-after-free in WebCore::RenderObject::enclosingLayer | - | 2016-10-02 |
101548 | Test: ABCD | - | 2016-10-02 |
101494 | OOB read in media::ScaleYUVToRGB32 | - | 2016-10-02 |
101458 | OOB read in WebM/vorbis vorbis_decode_frame() | $1,000 | 2016-10-02 |
101018 | Use after free in fullscreen unwraprenderer | - | 2016-10-02 |
101010 | Security: css/CSSParser.cpp memory corruption bug | - | 2016-10-02 |
100958 | Heap-use-after-free WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
100879 | Problem with full-screen infobar permission prompt | - | 2016-10-02 |
100863 | OOB read in SVG at WebCore::parseArcFlag | - | 2016-10-02 |
100543 | OOB read in WebM/vorbis at render_line() | $500 | 2016-10-02 |
101065 | Use after free with counters and inline-table and :before content | - | 2016-10-02 |
101127 | BlackBerryĂÂź | - | 2016-10-02 |
101136 | Security: Search terms hijacked to return only one site for search terms | - | 2016-10-02 |
138210 | Information and credential disclosure by file:// URLs (Android) | $500 | 2016-10-02 |
138035 | Security: Google Chrome for Android: Current-tab cross-application scripting (UXSS) | $500 | 2016-10-02 |
138012 | Heap-buffer-overflow in WebCore::FontCache::releaseFontData | - | 2016-10-02 |
137912 | Heap-buffer-overflow in WebCore::DelayDSPKernel::process | - | 2016-10-02 |
137891 | Security: HTTPS proxy can run JavaScript on requested HTTPS sites | - | 2016-10-02 |
137852 | Heap-use-after-free in WebKit::WebElement::document | - | 2016-10-02 |
137778 | Heap-use-after-free in webkit::ppapi::PPB_URLLoader_Impl::FillUserBuffer | - | 2016-10-02 |
138208 | Crash in SkGlyphCache::findImage | $1,000 | 2016-10-02 |
100492 | Use after free in WebM/matroska at matroska_execute_seekhead() | $3,000 | 2016-10-02 |
100465 | OOB read in OGV at unpack_vlcs | $500 | 2016-10-02 |
100464 | Use-after-free in WebM at decode_mb_mode | $1,000 | 2016-10-02 |
100459 | Use after free in RenderDeprecatedFlexibleBox::layoutHorizontalBox(bool) [and first-letter] | - | 2016-10-02 |
100447 | ClusterFuzz Account Check. | - | 2016-10-02 |
100322 | Security: Calling arbitrary V8 native functions from JavaScript | - | 2016-10-02 |
138196 | Stack-buffer-overflow in NPObjectProxy::NPNEvaluate | - | 2016-10-02 |
138192 | Heap-buffer-overflow in WebCore::HTMLInputElement::dataList | - | 2016-10-02 |
100526 | Use after free in floats and first-letter | - | 2016-10-02 |
137623 | Heap-buffer-overflow in WebPluginDelegateProxy::BackgroundChanged | - | 2016-10-02 |
137532 | Security: Android APIs exposed to JavaScript | $500 | 2016-10-02 |
137471 | Heap-use-after-free in WebCore::Element::cloneElementWithoutChildren | - | 2016-10-02 |
137413 | Heap-buffer-overflow in WebCore::RenderTableSection::setCellLogicalWidths | - | 2016-10-02 |
137409 | Heap-use-after-free in WebCore::RenderObject::container | - | 2016-10-02 |
137407 | Security: Chrome for iOS security bug | - | 2016-10-02 |
137364 | Heap-use-after-free in WebCore::CSSFontSelector::beginLoadTimerFired | - | 2016-10-02 |
137707 | Security: Chrome extensions bug cause crash in all Chrome processes | $500 | 2016-10-02 |
137671 | Security: Bad cast in WebCore::CalendarPickerElement::hostInput() | $2,000 | 2016-10-02 |
137541 | Reproduceable crash. Changing tabs while a specific text field has focus. | - | 2016-10-02 |
137233 | Heap-buffer-overflow in WebCore::RenderBlock::handleTrailingSpaces | - | 2016-10-02 |
137125 | UNKNOWN in WebCore::StylePropertySet::addParsedProperties | $1,000 | 2016-10-02 |
137208 | Security: Mouse lock permission and iframe on different host | - | 2016-10-02 |
137174 | UNKNOWN in WebCore::SVGAnimationElement::currentValuesForValuesAnimation | - | 2016-10-02 |
137147 | UNKNOWN in WebCore::RenderTable::cellBefore | - | 2016-10-02 |
137303 | Corrupted rendering with many MapsGL tabs open | - | 2016-10-02 |
137052 | Heap-use-after-free in WebCore::EllipsisBox::paint | - | 2016-10-02 |
137363 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
137362 | Heap-buffer-overflow in WebCore::CCLayerTreeHostImpl::CullRenderPassesWithNoQuads::shouldRemoveRenderPass | - | 2016-10-02 |
137232 | UNKNOWN in WebCore::ElementAttributeData::addAttribute | - | 2016-10-02 |
136497 | Security: XSS via Copy&Paste protection bypass using @formaction / General Iframe Sandbox Considerations regarding copy&paste / drag&drop | - | 2016-10-02 |
136881 | Security: race condition with workers and sync xmlhttprequests | $500 | 2016-10-02 |
136894 | Heap-buffer-overflow in UpsampleBgraLinePairSSE2 | $1,000 | 2016-10-02 |
136952 | Heap-use-after-free in WebCore::RenderLineBoxList::dirtyLinesFromChangedChild | - | 2016-10-02 |
136226 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
136182 | Heap-use-after-free in WebCore::ImageLoader::updateRenderer | - | 2016-10-02 |
136344 | Heap-use-after-free in WebCore::FrameLoader::stopAllLoaders | - | 2016-10-02 |
136116 | Heap-use-after-free in WebCore::RenderLayer::enclosingFilterLayer | - | 2016-10-02 |
136046 | Bad intersection of injected HTTP headers leads to Content Security Policy (CSP) Bypass | - | 2016-10-02 |
136296 | Heap-use-after-free in WebCore::SVGSMILElement::resetTargetElement | - | 2016-10-02 |
136235 | Heap-use-after-free in WebCore::StyleResolver::collectMatchingRulesForList | $1,000 | 2016-10-02 |
136145 | Security: Heap-buffer-overflow on TextFieldDecorationElement::defaultEventHandler | - | 2016-10-02 |
135697 | Heap-use-after-free in WebCore::RenderLayer::repaintBlockSelectionGaps | - | 2016-10-02 |
135658 | Turn off <iframe> seamless for m21 | - | 2016-10-02 |
135595 | Heap-use-after-free in WebCore::ImageLoader::notifyFinished | - | 2016-10-02 |
135705 | Heap-buffer-overflow in WebCore::TextIterator::handleTextBox | - | 2016-10-02 |
135432 | Heap-buffer-overflow in skia::BGRAConvolve2D | $1,000 | 2016-10-02 |
135698 | Heap-use-after-free in WebCore::HTMLInputElement::isPresentationAttribute | - | 2016-10-02 |
135485 | SPDY - Pushed stream - crash accessing https://jetty.intalio.com:10111/spdy | - | 2016-10-02 |
135071 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::append<unsigned short> | - | 2016-10-02 |
134897 | Bad cast with run-ins and <input> | $1,000 | 2016-10-02 |
135173 | Heap-use-after-free in WebCore::RenderQuote::rendererRemovedFromTree | - | 2016-10-02 |
135043 | Heap-use-after-free in media_stream:: | $3,133 | 2016-10-02 |
134429 | Heap-use-after-free in WebCore::Document::clearNodeListCaches | - | 2016-10-02 |
134639 | Heap-use-after-free in WebCore::RenderObject::destroyAndCleanupAnonymousWrappers | - | 2016-10-02 |
134428 | Heap-buffer-overflow in WebCore::SVGDocumentExtensions::removeAnimationElementFromTarget | - | 2016-10-02 |
134519 | Security: memory address disclosure through JavaScript in WebUI's cookies page | - | 2016-10-02 |
134402 | Heap buffer overflows in WebCore::CSSParser::lex | - | 2016-10-02 |
134324 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
134325 | Security: Use after free with mouse lock and window.open | $1,000 | 2016-10-02 |
100177 | Use after free in first-letter container destruction handling. | - | 2016-10-02 |
100149 | Use after free in AX Scrollbars | - | 2016-10-02 |
99991 | Use after free in ImageBuffer::toDataURL | - | 2016-10-02 |
100059 | Generic fix: Register custom fonts at creation time, rather than retire time. | $1,337 | 2016-10-02 |
99652 | OOB read in vp8_decode_frame | $1,000 | 2016-10-02 |
99732 | Use after free in table parts. | - | 2016-10-02 |
99603 | Use after free due to flexible box not laying some of its children. | - | 2016-10-02 |
99597 | Use after free in tables, float, :after content | - | 2016-10-02 |
99840 | Windows OpenGL performance drops by 2/3 with GPU sandbox on | - | 2016-10-02 |
99880 | Use after free in table :before, :after content. | $1,000 | 2016-10-02 |
99901 | BinScope reports SafeSEH not supported on video DLLs | - | 2016-10-02 |
99615 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | - | 2016-10-02 |
99465 | Security: AccessibilityImageMapLink holds onto it's parent even after it's been freed | - | 2016-10-02 |
99348 | Use after free in tables | - | 2016-10-02 |
99338 | Use after free in RenderTableSection::splitColumn | - | 2016-10-02 |
99596 | Use after free in media::FFmpegDemuxerStream::Read | - | 2016-10-02 |
99553 | repeatedly re-setting video.src crashes in WebCore::VideoLayerChromium::updateCompositorResources | - | 2016-10-02 |
99480 | OOB read in media::ScaleYUVToRGB32 | - | 2016-10-02 |
99294 | Use after free with :after in display table and :first-letter | $1,000 | 2016-10-02 |
99167 | [LangFuzz] Crash on Heap involving GC (invalid write) | $1,000 | 2016-10-02 |
99104 | WebKit: invalid cast in WebCore::toRenderBlock / WebCore::RenderBlock::blockSelectionGaps | - | 2016-10-02 |
99016 | Security: HTTPS Address Bar Spoofing Using View-source And Redirection | $1,000 | 2016-10-02 |
99003 | changing proxy | - | 2016-10-02 |
99229 | WebKit: Use after free in ~Node because ~HTMLLinkElement triggers script execution | - | 2016-10-02 |
99211 | Heap buffer overflow in Webaudio FFTFrame::doFFT | $2,000 | 2016-10-02 |
99138 | Use-after-free with plugin and editing | $1,000 | 2016-10-02 |
98556 | Use after free with first-letter | $1,000 | 2016-10-02 |
98262 | Chrome 16 crash when resizing window | - | 2016-10-02 |
98161 | Bug 68816 - Rapidly refreshing a feMorphology[erode] with r=0 can sometimes cause display corruption | - | 2016-10-02 |
98773 | [LangFuzz] Crash at v8::Object::SlowGetPointerFromInternalField with invalid read | $1,000 | 2016-10-02 |
98809 | Renderer crash with PDF at isalnum | $500 | 2016-10-02 |
98582 | Security: invalid memory reference to window object | - | 2016-10-02 |
97994 | Use after free due to stale fonts | - | 2016-10-02 |
97952 | Stale layout root generic fix from Mitz | - | 2016-10-02 |
97898 | Regression: Use after free in RenderBlock::linkToEndLineIfNeeded | - | 2016-10-02 |
97867 | Security: Major Google Plus and Google Chrome Problem | - | 2016-10-02 |
98089 | memory corruption in ANGLE shader translator | - | 2016-10-02 |
98064 | Use-after-free when font is missing | $1,000 | 2016-10-02 |
97784 | [v8] Stale pointer in CSSStyleSheet, Invalid cast in V8ListenerList::doFindWrapper | $1,500 | 2016-10-02 |
97608 | Use after free in counters in :before, :after content | $500 | 2016-10-02 |
97596 | Security: anonymous proxy | - | 2016-10-02 |
97553 | Clicking a link on a page that has been fullscreened by JS doesn't exit fullscreen | - | 2016-10-02 |
97546 | Use after free in ruby text :after, :before content due to stale styles. | - | 2016-10-02 |
97278 | Security: Tracking bug for CachedResourceLoader::canRequest in a redirect chain | - | 2016-10-02 |
97148 | Crashes in PhishingDOMFeatureExtractor::ExtractFeaturesWithTimeout | - | 2016-10-02 |
97092 | Stale canvas used in WebCore::PlatformContextSkia::save() | $1,000 | 2016-10-02 |
97674 | Security: Extension can get at tabs details (url/title) without requesting tabs permission | - | 2016-10-02 |
97599 | More stale styles in listmarkers | $1,000 | 2016-10-02 |
96747 | Security: Magic iframe transfer vulnerability for Pepper/NaCl plugins | - | 2016-10-02 |
96902 | Use-after-free in findPlaceForCounter | $1,000 | 2016-10-02 |
97006 | Use after free due to issues in element detachment when entering fullscreen | - | 2016-10-02 |
96665 | Use after free in Element::recalcStyle due to reparenting issues in treebuilder | - | 2016-10-02 |
96382 | out-of-bounds access in Gradient::sortStopsIfNecessary | - | 2016-10-02 |
96292 | Use after free in media BufferedResourceLoader::Start | - | 2016-10-02 |
141815 | Heap-use-after-free in WebCore::RenderQuote::detachQuote | - | 2016-10-02 |
141651 | Heap-buffer-overflow in SkA8_Blitter::blitAntiH | $500 | 2016-10-02 |
141564 | Heap-use-after-free in WebCore::HTMLLinkElement::removedFrom | - | 2016-10-02 |
141462 | Extension resources that are not web accessible should not be able to be linked to from the web | - | 2016-10-02 |
141444 | Security: Support pinning for Google ccTLDs | - | 2016-10-02 |
141395 | UNKNOWN in v8::internal::SemiSpaceIterator::Next | $1,000 | 2016-10-02 |
96499 | Heap-use-after-free in WebCore::RenderLayer::updateVisibilityStatus | - | 2016-10-02 |
96444 | Freed scrollbar used in RenderScrollbarPart::imageChanged [not related to previous stale m_owner issues] | - | 2016-10-02 |
96149 | Use after free in WebCore::AudioChannel::sumFrom | - | 2016-10-02 |
141093 | Security: Dev only restriction for declarativeWebRequest does not seem to work | - | 2016-10-02 |
96150 | Use after free in OfflineAudioDestinationNode::notifyCompleteDispatch | - | 2016-10-02 |
140805 | Heap-use-after-free in WebCore::RenderRegion::restoreRegionObjectsOriginalStyle | - | 2016-10-02 |
140803 | Heap-buffer-overflow in SkA8_Blitter::blitH | $1,000 | 2016-10-02 |
140720 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
140656 | Heap-use-after-free in WebCore::CachedResource::didAddClient | $1,000 | 2016-10-02 |
140647 | UNKNOWN in ogg_calc_pts | - | 2016-10-02 |
140642 | Heap-buffer-overflow in SkDashPathEffect::SkDashPathEffect | - | 2016-10-02 |
96131 | Closing parent then child in gmail = sad tab | - | 2016-10-02 |
96170 | Use after free in InspectorPageAgent::resourceContent | - | 2016-10-02 |
140495 | Text box fails to render contents and does not accept user input. | - | 2016-10-02 |
140484 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
140368 | Security: heap-use-after-free in xsltGenerateIdFunction | - | 2016-10-02 |
140165 | Heap-buffer-overflow in vorbis_decode_frame | - | 2016-10-02 |
140142 | Heap-use-after-free in base::internal::WeakReference::is_valid | - | 2016-10-02 |
140532 | Heap-use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
140544 | Security: CSP doesn't turn off eval, etc. in Web Workers | - | 2016-10-02 |
140083 | [LangFuzz] Crash on heap trying to execute address 0x0000000200000000. | $1,000 | 2016-10-02 |
140045 | REGRESSION(r122498): Assertion failure: m_nodeListCounts is sometimes not zero in the Document destructor | - | 2016-10-02 |
139961 | Heap-use-after-free in WebCore::TargetListener::handleEvent [Stale target] | - | 2016-10-02 |
139814 | UAF in DOMContentLoaded | $2,000 | 2016-10-02 |
139789 | Heap-buffer-overflow in WebCore::CSSParser::updateLastSelectorLineAndPosition | - | 2016-10-02 |
139772 | AddressSanitizer reports a global buffer underflow in swizzle_for_size() in Mesa | - | 2016-10-02 |
139744 | Security: SSL compression infoleak | $5,337 | 2016-10-02 |
140085 | UNKNOWN in /mnt/scratch0/clusterfuzz/slave-bot/builds/revisions/asan-linux-release-149416/chrome+Unknown | - | 2016-10-02 |
139685 | OOB read atleast in WebCore::SVGListProperty<WebCore::SVGTransformList>::getItemValuesAndWrappers | - | 2016-10-02 |
139690 | Heap-use-after-free in WebCore::GenericEventQueue::timerFired | - | 2016-10-02 |
139646 | Heap-use-after-free in WebCore::DynamicNodeList::itemWithName | - | 2016-10-02 |
139679 | Bad cast in RenderFrameSet::computeEdgeInfo | - | 2016-10-02 |
139530 | Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
139475 | Heap-use-after-free in WebCore::TargetListener::handleEvent [Stale event listener] | - | 2016-10-02 |
139462 | Heap-use-after-free in SkCanvas::updateDeviceCMCache | - | 2016-10-02 |
139541 | UNKNOWN in v8::HandleScope::CreateHandle | - | 2016-10-02 |
139464 | Heap-use-after-free in WebCore::RenderSVGShape::calculateStrokeBoundingBox | - | 2016-10-02 |
139321 | Heap-use-after-free in WebCore::InlineBox::extractLine | - | 2016-10-02 |
139402 | Heap-use-after-free in D_Clear_BitmapXferProc | - | 2016-10-02 |
139215 | Heap-use-after-free in WebCore::StyleResolver::collectMatchingRules | - | 2016-10-02 |
139168 | Security: Creating a loop in the DOM tree (99% a DoS) | $500 | 2016-10-02 |
139131 | Heap-use-after-free in WebCore::StyleResolver::collectMatchingRulesForList | - | 2016-10-02 |
139290 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImage | - | 2016-10-02 |
139383 | Heap-use-after-free in WebCore::HTMLTextFormControlElement::fixPlaceholderRenderer | - | 2016-10-02 |
139240 | Heap-buffer-overflow in WebCore::TextTrackCueList::add | - | 2016-10-02 |
138738 | Crash in extensions::SetContentSettingFunction | - | 2016-10-02 |
138915 | Heap-use-after-free in WebCore::ContainerNode::cloneChildNodes | - | 2016-10-02 |
138422 | Heap-use-after-free in WebCore::Font::glyphDataAndPageForCharacter | - | 2016-10-02 |
138404 | Heap-use-after-free in WebCore::Document::page | - | 2016-10-02 |
138673 | Heap-buffer-overflow in xsltApplyTemplates | $1,000 | 2016-10-02 |
138990 | Heap-use-after-free in WebCore::SVGStyledElement::clearHasPendingResourcesIfPossible | - | 2016-10-02 |
138672 | Heap-double-free in xsltCompileStepPattern | - | 2016-10-02 |
138901 | Heap-use-after-free in ProfileKeyedBaseFactory::GetProfileToUse | - | 2016-10-02 |
138302 | Stack-buffer-overflow in NPObjectProxy::NPInvokePrivate | - | 2016-10-02 |
138318 | UXSS with pointer lock | - | 2016-10-02 |
138382 | Heap-use-after-free in WebCore::AutoTableLayout::recalcColumn | - | 2016-10-02 |
138316 | Heap-use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
95849 | Security: any Chrome committer (or parhaps even any user with Google account?) can compromise Google Chrome | - | 2016-10-02 |
95842 | Security: Chrome Gives Unreliable Security Info | - | 2016-10-02 |
95761 | Use after free in ContainerNode::removeChild (looks related to plugin) | - | 2016-10-02 |
95672 | Use after free in ListIterms and RunIns rendering (from bug 88680) | $1,000 | 2016-10-02 |
95669 | Regression(r93913): Use after free in ScriptController::executeScript | - | 2016-10-02 |
95992 | Security: header injection when using embeded \0 in headerline | - | 2016-10-02 |
95920 | [LangFuzz] Crash at v8::internal::ElementsAccessorBase with invalid read | $1,000 | 2016-10-02 |
95917 | Security: Chrome does not ask for approval when "not trusted" SSL cert. changes | - | 2016-10-02 |
95563 | OOB read in tibetan_nextSyllableBoundary | - | 2016-10-02 |
95625 | OOB read in gpu::gles2::GLES2DecoderImpl::HandleDrawArrays | - | 2016-10-02 |
95499 | Use after free due to style not updated and having stale fonts. | - | 2016-10-02 |
95485 | [LangFuzz] Crash at v8::internal::Object::Lookup | $1,000 | 2016-10-02 |
95639 | Use after free in Document::fullScreenChangeDelayTimerFired | - | 2016-10-02 |
95620 | use-after-free in browser_tests | - | 2016-10-02 |
95520 | Child not placed correctly when :before, :after placed in same table part container causing stale style | - | 2016-10-02 |
95359 | Use after free in WebCore::SVGTRefElement::updateReferencedText | - | 2016-10-02 |
95360 | use after free in WebCore::ContainerNode::removeChild via Range.deleteContents() | - | 2016-10-02 |
95083 | Security: Reveal stored passwords using the Developer Tool | - | 2016-10-02 |
95072 | Use after free due to style not updated for svg text runs. | $1,000 | 2016-10-02 |
95012 | Add defensive bounds checking in AudioNode | - | 2016-10-02 |
94834 | Security: Thread safety with AudioChannelMerger | - | 2016-10-02 |
95374 | Redirect to chrome:// URIs via Location: header | $2,337 | 2016-10-02 |
95465 | 4 OOB reads in XMLDocumentParser::doWrite | - | 2016-10-02 |
95333 | ERROR:the following pages have become unresponsive. you can wait to become responsive or kill them | - | 2016-10-02 |
94820 | Don't allow nodes of one context to be connected to nodes of another context | - | 2016-10-02 |
94743 | Regression(r93913): Use after free in ScheduledAction::execute(WebCore::V8Proxy*) | - | 2016-10-02 |
94578 | Security: Brute forcing Intranet WWW-Auth with script element | - | 2016-10-02 |
94487 | Security: JSC::Yarr regexp 32/48 to the left of 768 with workers | $1,000 | 2016-10-02 |
94464 | Security: e | - | 2016-10-02 |
94463 | Security: e | - | 2016-10-02 |
94462 | Security: e | - | 2016-10-02 |
94461 | Security: e | - | 2016-10-02 |
94460 | Security: e | - | 2016-10-02 |
94459 | Security: e | - | 2016-10-02 |
94458 | Security: e | - | 2016-10-02 |
94810 | Use after free with Floats and Ruby | - | 2016-10-02 |
94809 | Use after free in ruby overhang. | - | 2016-10-02 |
94456 | Security: | - | 2016-10-02 |
94275 | Make sure that AudioArray is 16-byte aligned | - | 2016-10-02 |
94273 | V8 custom bindings for AudioNode must do proper object checking and throw exception in case of error | - | 2016-10-02 |
94186 | WebAudio node lifetype crash when tearing down audio nodes / media element node | - | 2016-10-02 |
94025 | WebAudio: Integer overflows in AudioArray | - | 2016-10-02 |
93978 | Out of bounds reads and writes when FFT size is changed. | - | 2016-10-02 |
93918 | Regression(93122): Use after free in InspectorCSSAgent::clearFrontend | - | 2016-10-02 |
94457 | Security: e | - | 2016-10-02 |
94278 | Fix thread-safety of AudioNode deletion | - | 2016-10-02 |
93596 | Bad read in bundled PDF viewer | - | 2016-10-02 |
93497 | Security: Accessibility of the chrome.webstorePrivate-API | - | 2016-10-02 |
93472 | Yet another double-free caused by malformed XPath expression in XSLT | $1,000 | 2016-10-02 |
93420 | Use after free in FocusController::advanceFocusInDocumentOrder | $1,000 | 2016-10-02 |
93788 | Use after free in RenderText lineboxes. | $1,000 | 2016-10-02 |
93587 | Use after free in WebCore::Text::recalcStyle due to before after content issue in table parts | $1,000 | 2016-10-02 |
93856 | Use after free in RenderFlowThread::nextRendererForNode | - | 2016-10-02 |
93146 | Security: Possible race condition in Windows Policy reading that can lead to stale policy. | - | 2016-10-02 |
93106 | Failing assertion in IDBTransaction.cpp | - | 2016-10-02 |
93097 | Defensively null out danging pointers in the NaCl browser plugin memory safety for M14 | - | 2016-10-02 |
93059 | OOB read in EventDispatcher::adjustToShadowBoundaries | - | 2016-10-02 |
93416 | Security: Arbitrary cross-origin bypass using __defineGetter__ prototype override | $2,000 | 2016-10-02 |
93236 | Stale Pointer Crash in PrintWebViewHelper::PrintPreviewContext::CreatePreviewDocument | - | 2016-10-02 |
92959 | Stale node in StyleSheetCandidateListHashSet | $1,000 | 2016-10-02 |
92769 | Use after free in TreeBuilder | - | 2016-10-02 |
92651 | Use after free due to style not updated for ANONYMOUS boxes (e.g RenderRow), inline-blocks (e.g. RenderRubyRun) | $1,000 | 2016-10-02 |
92621 | Use after free in VisibleSelection::selectionFromContentsOfNode | - | 2016-10-02 |
92550 | Chrome (main process) crashes when setVersion is called when all (Indexed) database name space is used up | - | 2016-10-02 |
92226 | Use after free in CounterNode::lastDescendant | - | 2016-10-02 |
92840 | Use after free in HarfbuzzFace::~HarfbuzzFace | - | 2016-10-02 |
146433 | Chrome_Mac: Crash Report - base::::CrMallocErrorBreak / invalid free in SkWriter32::rewindToOffset | - | 2016-10-02 |
146235 | WTF::equal is too aggressive and may trigger ASan reports | - | 2016-10-02 |
146208 | Heap-buffer-overflow in WebCore::RenderTableSection::nodeAtPoint | - | 2016-10-02 |
146145 | Heap-use-after-free in WebCore::RenderText::computePreferredLogicalWidths | - | 2016-10-02 |
146144 | Heap-use-after-free in WebCore::FrameView::scrollContentsFastPath | - | 2016-10-02 |
146111 | Heap-use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
145976 | Heap-use-after-free in WebCore::HTMLTextFormControlElement::fixPlaceholderRenderer | - | 2016-10-02 |
145921 | AddressSanitizer reports a UAF in WebCore::RenderStyle::letterSpacing | - | 2016-10-02 |
146146 | Heap-buffer-overflow in WebCore::FlowThreadController::unregisterNamedFlowContentNode | - | 2016-10-02 |
145867 | Heap-use-after-free in WebCore::FrameView::scrollContentsFastPath | - | 2016-10-02 |
145915 | Security/Privacy: <img>-embedded SVG will load external content referenced by CSS @import @font-face | - | 2016-10-02 |
145530 | Mitigation: Kill OOB reads(or few writes) by preventing access to harmful locals in dirty text lineboxes | - | 2016-10-02 |
145525 | Security: heap buffer overflow in gpu process with webgl | $3,500 | 2016-10-02 |
145492 | Web Inspector: Page with @import and :last-child in an edited stylesheet will crash (UAF) | - | 2016-10-02 |
145544 | Security: integer overflow in gpu process with webgl | $1,000 | 2016-10-02 |
145272 | Heap-use-after-free in WebCore::nextBreakablePosition | - | 2016-10-02 |
145018 | Heap-use-after-free in WebCore::StyleSheetContents::checkLoadCompleted | - | 2016-10-02 |
144886 | Security: webgl crash on mesa | $3,133 | 2016-10-02 |
144866 | Security: Chrome for Android Bypassing SOP for Local Files By Symlinks | $500 | 2016-10-02 |
144831 | Heap-buffer-overflow in WebCore::StylePropertySet::copyPropertiesFrom | - | 2016-10-02 |
145363 | Security: Chrome extension DEP crash | - | 2016-10-02 |
144899 | SkPaint::SkPaint - crash | $1,000 | 2016-10-02 |
144799 | Heap-double-free in xmlFreeNodeList | - | 2016-10-02 |
144813 | Security: UXSS via com.android.browser.application_id Intent extra | $500 | 2016-10-02 |
144671 | Heap-use-after-free in WebCore::GCPrologueVisitor<void, WebCore::SpecialCasePrologueObjectHandler>::visitDOMWrapper | - | 2016-10-02 |
144466 | Crash when verifying ECDSA certificate on XP | - | 2016-10-02 |
144734 | Heap-buffer-overflow in WebCore::RenderTable::removeCaption | - | 2016-10-02 |
144810 | Heap-use-after-free in WebCore::RenderTable::calcBorderEnd | - | 2016-10-02 |
144704 | Tracking bug for fixing rel=noreferrer aslr bypass | - | 2016-10-02 |
143761 | Heap-use-after-free in WebCore::GraphicsContext::restore | $1,000 | 2016-10-02 |
143672 | Flapper Crash in BrokerProcessDispatcher::GetSitesWithData | - | 2016-10-02 |
143859 | Security: World-writable shared memory segments for X/Linux UI | - | 2016-10-02 |
144051 | Security: Memory address disclosure through JavaScript in Print Preview WebUI | - | 2016-10-02 |
143846 | Security: Chromoting creates a world-writable shared memory segment | - | 2016-10-02 |
143609 | Heap-use-after-free in WebCore::ElementV8Internal::onclickAttrGetter | $1,000 | 2016-10-02 |
143604 | Heap-use-after-free in WebCore::RenderBlock::LineBreaker::nextLineBreak [SVG text] | - | 2016-10-02 |
143593 | Heap-buffer-overflow in WebCore::SurrogatePairAwareTextIterator::consume | - | 2016-10-02 |
143582 | Heap-use-after-free in WTF::OwnPtr<WTF::Vector<WebCore::RegisteredEventListener, 1ul> >::~OwnPtr | - | 2016-10-02 |
143551 | Heap-use-after-free in WebCore::TreeScopeAdopter::moveTreeToNewScope | - | 2016-10-02 |
143656 | Heap-use-after-free in WebCore::SVGTRefElement::updateReferencedText | $1,000 | 2016-10-02 |
143648 | Heap-buffer-overflow in WebCore::StyleResolver::applyProperty | - | 2016-10-02 |
143176 | Heap-use-after-free in WebCore::AccessibilityNodeObject::document | - | 2016-10-02 |
143409 | Heap-buffer-overflow in SkScalerContext_FreeType::generateImage | - | 2016-10-02 |
142956 | Security: XSS in SSL Certificate error page | $500 | 2016-10-02 |
142876 | Heap-buffer-overflow in WebCore::HarfBuzzShaperBase::isWordEnd | - | 2016-10-02 |
143329 | Bad cast in RenderGrid::layoutGridItems | - | 2016-10-02 |
143004 | Security: Untrustworthy Chrome OS user-wallpaper png's are loaded pre-login (in the sandboxed utility process) | - | 2016-10-02 |
142310 | ASan reports a use-after-free in IndexedDBBrowserTest.Bug109187Test | - | 2016-10-02 |
142395 | Bad cast in computeReplacedLogicalHeightUsing | - | 2016-10-02 |
142145 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
142746 | Security: Potential use after destruction in ui/gfx/image | - | 2016-10-02 |
142169 | Heap-buffer-overflow in SkAlphaRuns::add | $500 | 2016-10-02 |
142088 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
142087 | UNKNOWN in void v8::internal::String::WriteToFlat<char> | - | 2016-10-02 |
141901 | Security: mesa stack scribbling thingamadoo | $3,133 | 2016-10-02 |
141889 | Security: Cookie theft from Chrome by malicious Android app | $500 | 2016-10-02 |
91972 | Regression(85705): Use after free on m_originatingLine in floats | - | 2016-10-02 |
91940 | Security: Romanian colloquialism meaning penis when viewing YouTube channels | - | 2016-10-02 |
91939 | Security: Romanian colloquialism meaning penis when viewing YouTube channels | - | 2016-10-02 |
91921 | Use after free in RenderRubyBase | - | 2016-10-02 |
91911 | Freed m_renderer used in InlineBox::deleteLine | - | 2016-10-02 |
91973 | Regression(90971): Use after free in Textarea placeholder | - | 2016-10-02 |
91665 | Crash on bad rip when opening a PDF | $1,000 | 2016-10-02 |
91801 | Use after free of RootInlineBox | - | 2016-10-02 |
91577 | file:// URL access is defaulting to opt-in | - | 2016-10-02 |
91554 | Possible use-after-free in AddToConsole | - | 2016-10-02 |
91633 | Security: When upgrade to 13.0.782.107, chrome will run js and load image which had be disabled in chrome | - | 2016-10-02 |
91502 | Security: Malware Page forbids user from closing a tab.(window.onunload hijack) | - | 2016-10-02 |
91362 | Regression(91331): Bad cast due to html renderer created for svg glyphref | - | 2016-10-02 |
91312 | Security: Native Client app can crash trusted code. | - | 2016-10-02 |
91218 | XSS in chrome://appcache-internals | - | 2016-10-02 |
91517 | Security: V8 asserts (crashes) when entering simple JS snippit | - | 2016-10-02 |
91321 | Regression(91788): Bad cast in WebCore::blockWithNextLineBox | - | 2016-10-02 |
91020 | Use after free in MediaTest.FLAKY_VideoBearWebm on Mac OS | - | 2016-10-02 |
91099 | OOB read in RenderScrollbarPart::computeScrollbarWidth | - | 2016-10-02 |
91120 | [LangFuzz] Crash at Runtime_QuoteJSONString with invalid write | $500 | 2016-10-02 |
91082 | Security: Major Privacy Loop Hole ! | - | 2016-10-02 |
91079 | where to submit Google account bug | - | 2016-10-02 |
91093 | Bad cast in paintMediaPlayButton | - | 2016-10-02 |
91016 | Security: Canvas toDataURL security error: It is taking page information and not the canvas when making the image | $500 | 2016-10-02 |
91013 | [LangFuzz] Crash at RootMarkingVisitor::VisitPointers (32 bit) | $1,000 | 2016-10-02 |
91010 | [LangFuzz] Crash at JSObject::SetDictionaryElement with invalid read (32 bit) | $1,000 | 2016-10-02 |
91197 | Use after free or bad cast with empty .swf file | - | 2016-10-02 |
91092 | Use after free in SVGUseElement::buildShadowTree | - | 2016-10-02 |
90978 | read out of bounds in sUnpremultiplyData_RGBA8888 / ImageBufferData::getData (WEBKIT 65352) | - | 2016-10-02 |
90668 | Use after free in WebCore::findPlainText | $1,000 | 2016-10-02 |
90498 | Security: automatically downloading of .crdownload-files | - | 2016-10-02 |
91008 | [LangFuzz] Crash at JSObject::PrepareElementsForSort with invalid read | $1,000 | 2016-10-02 |
90357 | OOB read in WebCore::previousBoundary | - | 2016-10-02 |
90217 | Prevent silent truncation of trailing characters in downloaded file names | - | 2016-10-02 |
90173 | OOB read in media::ScaleYUVToRGB32 due to failure to account for zero source width and accessing negative indices | - | 2016-10-02 |
90134 | OOB read in harfbuzz with khmer character | - | 2016-10-02 |
90105 | Heap-buffer-overflow in WebCore::RenderBlock::LineBreaker::nextLineBreak | - | 2016-10-02 |
89991 | Regression(82144): OOB InlineIterator read in TrailingObjects::updateMidpointsForTrailingBoxes | $500 | 2016-10-02 |
90175 | Security: remove any site from Google Index | - | 2016-10-02 |
89795 | Browser crash in net::WebSocketJob::SendPending | - | 2016-10-02 |
89580 | Use after free due to continuation splitting issues in -webkit-column-span | - | 2016-10-02 |
89599 | Freed SVGTRefElement used in SVGStyledElement::buildPendingResourcesIfNeeded | - | 2016-10-02 |
89836 | Tracking bug for ANGLE memory corruption on Windows | $1,337 | 2016-10-02 |
89575 | Use after free of markers in CompositeEditCommand::replaceTextInNodePreservingMarkers | - | 2016-10-02 |
89564 | Possible URL Bar Spoofing when history.forward() is ignored using forward button | $500 | 2016-10-02 |
89678 | Use after free in ReplacementFragment::removeUnrenderedNodes | - | 2016-10-02 |
89552 | Use after free in CSSStyleSheet::checkLoaded | - | 2016-10-02 |
89522 | SVG animation API crashes on SVGAnimateTransform | - | 2016-10-02 |
89511 | Use after free in IDBRequest::abort | - | 2016-10-02 |
89493 | Use after free in SVG foreignobject rendering. | - | 2016-10-02 |
89422 | Two use after frees in NPObjectStub | - | 2016-10-02 |
89558 | Use after free in SVGUseElement::buildShadowTree | $500 | 2016-10-02 |
89402 | Memory corruption (double free) caused by malformed XPath expression in XSLT | $1,000 | 2016-10-02 |
89330 | DocumentLoader use after free in KURL::strippedForUseAsReferrer | $1,000 | 2016-10-02 |
89219 | Use after free due to document destruction within unload event | $1,000 | 2016-10-02 |
89142 | PDF viewer crash | $500 | 2016-10-02 |
89020 | Security: ftp | - | 2016-10-02 |
88976 | possible use after free WebCore::FontCache::getFontDataForCharacters | - | 2016-10-02 |
88949 | Security: Location Bar Spoofing using very long string on a web address in the location bar | - | 2016-10-02 |
88944 | Use-after free in leveldb | $3,133 | 2016-10-02 |
88932 | Security: Exploit in google+ | - | 2016-10-02 |
152691 | chrome!std::_Tree<std::_Tmap_traits<tracked_objects::Location,tracked_objects::Births *,std::less<tracked_objects::Location>,std::allocator<std::pair<tracked_objects::Location const ,tracked_objects::Births *> >,0> >::find+15 - crash | $2,000 | 2016-10-02 |
152585 | Heap-use-after-free in WebCore::ContainerNode::removeAllChildren | - | 2016-10-02 |
152420 | Heap-use-after-free in content::P2PSocketClient::OnDataReceived | - | 2016-10-02 |
152354 | Mask RenderArena freelist entries. | - | 2016-10-02 |
152569 | Chrome_Mac: Crash Report - Stack Signature: CompositorOutputSurface::OnMessageReceived-... | $500 | 2016-10-02 |
152442 | Heap-use-after-free in icu_46::RuleBasedCollator::RuleBasedCollator | - | 2016-10-02 |
151895 | Defense to throw "unauthorized" infobar for excessively crashing plug-in does not work for Pepper Flash! | - | 2016-10-02 |
151888 | Crash in v8::internal::SlotsBuffer::UpdateSlotsRecordedIn | - | 2016-10-02 |
151854 | Heap-use-after-free in WebCore::CachedResource::addClientToSet | - | 2016-10-02 |
151795 | Security: remove chrome.experimental.offscreenTabs API | - | 2016-10-02 |
152104 | out of bounds array access in WTF::TypedArrayBase<unsigned char>::item(unsigned int) / WebCore::FEMorphology::platformApplyGeneric | - | 2016-10-02 |
151992 | Heap-use-after-free in VideoCaptureImpl::RemoveClient | - | 2016-10-02 |
151860 | Heap-use-after-free in WebCore::DateTimeFieldElement::didBlur | $1,000 | 2016-10-02 |
151008 | Heap-use-after-free in WebCore::CanvasRenderingContext2D::setFont | $1,000 | 2016-10-02 |
151424 | Chrome: Crash Report - Stack Signature: WebCore::CachedImage::likelyToBeUsedSoon()-... | - | 2016-10-02 |
151449 | Heap-buffer-overflow in cc::CCKeyframedTransformAnimationCurve::getValue | - | 2016-10-02 |
150966 | Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
151049 | Heap-use-after-free in WebCore::RenderObject::destroyAndCleanupAnonymousWrappers | - | 2016-10-02 |
150571 | Global-buffer-overflow in v128_copy_octet_string | - | 2016-10-02 |
150067 | Heap-buffer-overflow in WebCore::InlineFlowBox::placeBoxesInInlineDirection | - | 2016-10-02 |
149999 | Heap-use-after-free in WebCore::WebKitCSSSVGDocumentValue::load | - | 2016-10-02 |
150842 | Heap-use-after-free in content::P2PSocketClient::DeliverOnSocketCreated | - | 2016-10-02 |
150545 | UNKNOWN in v8::internal::RootMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
150650 | MSI installer ships an out-of-date GoogleUpdate.exe with no ASLR or DEP (and may not be updating) | - | 2016-10-02 |
150729 | UNKNOWN in v8::internal::Invoke | $1,500 | 2016-10-02 |
150737 | IndexedDB causes V8 heap corruption | $1,000 | 2016-10-02 |
149717 | Security: integer overflow in webgl on osx | $1,000 | 2016-10-02 |
149877 | Security: Omnibox drop target enables navigation to restricted URLs | - | 2016-10-02 |
149904 | Security: webgl - after running out of memory, buffer can still be written | $1,000 | 2016-10-02 |
149840 | Heap-use-after-free in WebCore::StyleRuleImport::setCSSStyleSheet | - | 2016-10-02 |
149871 | Untrustworthy navigation causes HTTP Basic Auth dialog origin confusion/spoofing | - | 2016-10-02 |
148612 | Heap-use-after-free in WebCore::pushFullyClippedState | - | 2016-10-02 |
148896 | UNKNOWN in v8::internal::ElementsAccessorBase<v8::internal::ExternalUnsignedByteElementsAccessor, v8::internal: | - | 2016-10-02 |
148378 | [LangFuzz] Crash due to invalid free in v8::internal::Runtime_RegExpExecMultiple | $1,000 | 2016-10-02 |
148692 | Heap-buffer-overflow in ucstrTextExtract | $500 | 2016-10-02 |
148638 | Heap-buffer-overflow in SkAAClipBlitter::blitAntiH | $500 | 2016-10-02 |
148567 | Touch events allow cross-origin access | $500 | 2016-10-02 |
147625 | Security: UXSS/SOP bypass with document.write (Chrome on iOS) | $500 | 2016-10-02 |
147499 | Heap-use-after-free in media::AudioOutputDevice::AudioThreadCallback::Process | $3,133 | 2016-10-02 |
147475 | UNKNOWN in v8::internal::Deoptimizer::DoComputeOutputFrames | - | 2016-10-02 |
147459 | Heap-use-after-free in WebCore::ImageLoader::updateRenderer | - | 2016-10-02 |
148376 | [LangFuzz] Crash at v8::internal::MarkCompactCollector::EvacuateNewSpace with invalid read | $1,000 | 2016-10-02 |
147700 | Heap-use-after-free in WebCore::Document::fullScreenChangeDelayTimerFired | - | 2016-10-02 |
147592 | Chrome_ChromeOS: Crash Report - Stack Signature: WebKit::WebWorkerClientImpl::openFileSystem... | - | 2016-10-02 |
146882 | Heap-use-after-free in WebCore::InlineBox::adjustPosition | - | 2016-10-02 |
146760 | Security: URL bar spoofing with SSL error messages (Chrome on iOS) | $500 | 2016-10-02 |
146725 | AddressSanitizer reports a use-after-free in WebKit::DateTimeChooserImpl::didClosePopup | - | 2016-10-02 |
147435 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
147436 | UNKNOWN in sk_memset32_SSE2 | - | 2016-10-02 |
147290 | Heap-use-after-free in WebCore::DateTimeEditElement::setEmptyValue | $1,000 | 2016-10-02 |
146492 | Check behavior of "," in "content_security_policy" manifest attribute. | - | 2016-10-02 |
88850 | Use after free with fuzzed ogv file | $1,000 | 2016-10-02 |
88846 | Use-after-free in FrameLoader with no form post method | $1,000 | 2016-10-02 |
88889 | Stale pointer due to floats not removed (flexible box display) | $1,000 | 2016-10-02 |
88858 | [LangFuzz] Crash at JSObject::LocalLookupRealNamedProperty with invalid read on gc | $1,000 | 2016-10-02 |
88757 | AudioContext GainNode memory corruption | - | 2016-10-02 |
88730 | Use after free in SVGUseElement::invalidateShadowTree / SVGElementInstance::invalidateAllInstancesOfElement | - | 2016-10-02 |
88723 | REGRESSION (r85964): Use after free in WebCore::RenderObject::localToAbsolute | - | 2016-10-02 |
88684 | Stale m_owner in RenderScrollbar (m_owner is deleted body element) | - | 2016-10-02 |
88670 | ZDI-CAN-1283: Webkit fontface Invalid Font Family Remote Code Execution Vulnerability | - | 2016-10-02 |
88649 | HRTFDatabaseLoader memory corruption | - | 2016-10-02 |
88647 | webkitAudioContext can be called as a function instead of a constructor. | - | 2016-10-02 |
88827 | OOB read due to Integer overflow in SkDashPathEffect constructor (len and phase) | - | 2016-10-02 |
88729 | Security: PPB_Graphics2D_Create will lead to integer overflow in shm alloc | - | 2016-10-02 |
88436 | Ogg memory corruption | - | 2016-10-02 |
88337 | The beforeload event allows tracking URI changes in a frame | $500 | 2016-10-02 |
88131 | Aw, Snap! with context.createBuffer(request.response, false) on certain files | - | 2016-10-02 |
88093 | Security: out-of-bounds read in v8 with defineProperty and arguments | $1,000 | 2016-10-02 |
88591 | [LangFuzz] CHECK(!value->IsTheHole()) failed // Crash with invalid read in shell | $1,000 | 2016-10-02 |
88531 | Use-after-free in SafeBrowsingResourceHandler::OnBrowseUrlCheckResult | - | 2016-10-02 |
88216 | Regression: Use-after-free in CounterNode::insertAfter | $1,000 | 2016-10-02 |
87861 | Security: OOB read in svg text run | - | 2016-10-02 |
87815 | chrome-devtools:// can be navigated from http | - | 2016-10-02 |
87746 | Security: Chrome content script listener | - | 2016-10-02 |
87925 | Use after free in range extract contents | $1,000 | 2016-10-02 |
87965 | webkitAudioContext multiple issues | - | 2016-10-02 |
87862 | Security: Use after free in svg text | - | 2016-10-02 |
87701 | Stale pointer in WebCore::PlatformContextSkia::save | - | 2016-10-02 |
87548 | use after free in skia blitter | - | 2016-10-02 |
87520 | Security: Webpage can gain access to extension content-script variables when content-script triggers events | - | 2016-10-02 |
87478 | [LangFuzz] Crash on heap with invalid read | $1,000 | 2016-10-02 |
87339 | XSS injection via prototype chain | $500 | 2016-10-02 |
87298 | OOB read due to iterating over wrong textbox in TextIterator::emitText (first-letter + RTL) | $500 | 2016-10-02 |
87729 | Use after free in third_party/WebKit/LayoutTests/fast/dom/HTMLLinkElement/link-and-subresource-test.html | $1,000 | 2016-10-02 |
87728 | Regression(89733): Use after free in fast/forms/text-control-intrinsic-widths.html | $1,000 | 2016-10-02 |
87120 | Use after free on 2-Step-Authentication-method-change | $500 | 2016-10-02 |
87148 | use after free due to floats not removed | $1,000 | 2016-10-02 |
86758 | URL Bar Spoofing using History.back() and History.forward | $500 | 2016-10-02 |
86705 | Use after free in Geolocation::fatalErrorOccurred | - | 2016-10-02 |
87227 | Use after free due to refcounting issue in MediaQueryMatcher::prepareEvaluator | $1,000 | 2016-10-02 |
86900 | Heap memory corruption in web database support (SQLite/ICU) | $1,000 | 2016-10-02 |
86502 | Use after free due to floats not cleared from parent's next siblings blocks (on losing ability to intrude floats) | $1,000 | 2016-10-02 |
86191 | Security: web-exposed manifest from Chrome extensions diverges from the real manifest in regards to NPAPI | - | 2016-10-02 |
86304 | Google Chrome Acess Violation in Frame manipulation | - | 2016-10-02 |
86609 | OOB read in fontfallbacklist due to issue in CSSPrimitiveValues clamping | - | 2016-10-02 |
86178 | URL bar introduces NUMEROUS vulnerabilities. | - | 2016-10-02 |
86648 | Use after free in formassociatedelement not removed from m_formElementsWithFormAttribute | - | 2016-10-02 |
86367 | Use after free of frame in Document::finishedParsing | - | 2016-10-02 |
85992 | Renderers can have registry handle which would allow a Windows sandbox escape | - | 2016-10-02 |
85943 | Use after free in Stylesheet due to issue in CLONE nodes | - | 2016-10-02 |
85808 | chrome_1c30000!webkit::ppapi::PPB_Widget_Impl::Invalidate crash | $500 | 2016-10-02 |
85559 | Web Inspector: Crash by buffer overrun crash when serializing inspector object tree. | - | 2016-10-02 |
86133 | Add GRP to dangerous file list | - | 2016-10-02 |
86108 | Security: FileSystem API can be used to learn about installed software on the user's computer | - | 2016-10-02 |
85418 | Use-after-free in WebCore::RenderTextControl::isSelectableElement | $1,000 | 2016-10-02 |
85309 | Crash when closing a child window that uses a canvas | - | 2016-10-02 |
85302 | Crasher in WebCore::StyleBase::stylesheet | - | 2016-10-02 |
85256 | OOB read in UniscribleController::advance | - | 2016-10-02 |
85211 | Use after free in SVGUseElement::buildShadowTree | $1,000 | 2016-10-02 |
85177 | Renderer crash with javascript + setInterval | $500 | 2016-10-02 |
85158 | Content script can gain access to the "window" object of the page using custom events | - | 2016-10-02 |
85350 | Browser Crash in ~TabContents caused by PrerenderManager::PeriodicCleanup | - | 2016-10-02 |
156906 | Heap-use-after-free in WebCore::XMLDocumentParser::doEnd | - | 2016-10-02 |
156826 | UNKNOWN in S32A_Blend_BlitRow32_SSE2 | - | 2016-10-02 |
156828 | UNKNOWN in WebCore::Font::drawGlyphs | - | 2016-10-02 |
156669 | Origin.com somehow manages to open its result page in the previous tab (which was gmail) | - | 2016-10-02 |
156619 | Heap-use-after-free in WebCore::ApplyStyleCommand::cleanupUnstyledAppleStyleSpans | - | 2016-10-02 |
156431 | Security: Use after free in IDBDatabaseCallbacksImpl::onVersionChange | - | 2016-10-02 |
156418 | Heap-use-after-free in SpellCheckHostImpl::SaveDictionaryData | - | 2016-10-02 |
156689 | Heap-buffer-overflow in WTF::StringImpl::findIgnoringCase | - | 2016-10-02 |
156567 | Security: use-after-free in WebCore::GraphicsContext::paintingDisabled | $1,000 | 2016-10-02 |
156282 | Heap-use-after-free in WebCore::StyleResolver::pseudoStyleRulesForElement | - | 2016-10-02 |
156383 | Security: chrome_to_device makes use of HTTP for cloudprint | - | 2016-10-02 |
156096 | Heap-buffer-overflow in WebCore::RenderBlock::LineBreaker::nextLineBreak | - | 2016-10-02 |
156231 | UNKNOWN in _wordcopy_fwd_aligned | $1,000 | 2016-10-02 |
156366 | Heap-use-after-free in PluginPlaceholder::ReplacePlugin | - | 2016-10-02 |
156152 | Issues with HSTS / public key pins state tracking | - | 2016-10-02 |
155977 | Security: remove uses of innerHTML in commented code for Getting Started Guide. | - | 2016-10-02 |
155860 | WebCore::SharedBuffer::append(data, 0) can cause unitialized memory to be added to the SharedBuffer | - | 2016-10-02 |
155711 | Security: forced oom in browser process due to indefinitely growing buffer in chunked decoder | - | 2016-10-02 |
155643 | Heap-use-after-free in content::RenderWidgetHostImpl::OnMsgInputEventAck | - | 2016-10-02 |
156015 | Heap-use-after-free in WebCore::FontPlatformData::uniqueID | - | 2016-10-02 |
156051 | Heap use-after-free in ExtensionFunctionDispatcher::Dispatch caught by ASan when using "Screen Capture by Google" | - | 2016-10-02 |
155877 | Chrome: RenderViewImpl::OnContextMenuClosed(content::CustomContextMenuContext const &) | - | 2016-10-02 |
155293 | Heap-use-after-free in WebCore::ContextMenu::appendItem | - | 2016-10-02 |
155285 | Heap-use-after-free in WebCore::Node::setNeedsStyleRecalc | - | 2016-10-02 |
155117 | Security: GetReadonlyPnaclFD IPC security issues | - | 2016-10-02 |
154987 | Pwnium SVG use after free | - | 2016-10-02 |
154983 | Security: Pwnium 2 TCMalloc profile bug | $60,000 | 2016-10-02 |
155421 | Security: javascript scheme links auto-generated in devtools console | - | 2016-10-02 |
154617 | Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
155323 | Out of bounds array access in GPU process | - | 2016-10-02 |
154926 | Heap-use-after-free in WebIntentPickerGtk::OnDestroyThunk | - | 2016-10-02 |
154488 | Heap-use-after-free in WebCore::FrameLoader::stopLoading | - | 2016-10-02 |
154465 | Bad cast in webkit_glue::GetSubResourceLinkFromElement | - | 2016-10-02 |
154460 | Heap-use-after-free in WebCore::ScrollableArea::scroll | - | 2016-10-02 |
154448 | Heap-use-after-free in TransportDIB::DecreaseInFlightCounter | - | 2016-10-02 |
154362 | Heap-buffer-overflow in WebCore::HTMLSelectElement::typeAheadFind | - | 2016-10-02 |
154590 | Stack-buffer-overflow in SkFontHost::GetAdvancedTypefaceMetrics | - | 2016-10-02 |
154485 | Heap-buffer-overflow in std::vector<scoped_refptr<printing::PrintJob>, std::allocator<scoped_refptr<printing::PrintJob> > >: | - | 2016-10-02 |
154158 | Security: ensure that a user has willing-fully logged-in to his Google account before triggering the one click Chrome login feature | - | 2016-10-02 |
154055 | Heap-use-after-free in WebCore::RenderLayerBacking::paintIntoLayer | $1,000 | 2016-10-02 |
153793 | Heap-use-after-free in WebCore::EventHandler::mouseMoved | - | 2016-10-02 |
153666 | Security: Bypass for consumable user gesture on pop-up | - | 2016-10-02 |
153592 | Heap-use-after-free in WebCore::RenderObject::isDescendantOf | - | 2016-10-02 |
154284 | Heap-use-after-free in WebCore::SVGTextRunRenderingContext::glyphDataForCharacter | - | 2016-10-02 |
154283 | Heap-buffer-overflow in _HB_GDEF_Check_Property | - | 2016-10-02 |
153469 | Security: Nvidia - Kernel Panic - [@ gpu::gles2::GLES2DecoderImpl::ResizeOffscreenFrameBuffer] | - | 2016-10-02 |
153239 | Heap-use-after-free in WebCore::GCEpilogueVisitor<void, WebCore::SpecialCaseEpilogueObjectHandler, &WebCore::DOMDataStore:: | - | 2016-10-02 |
153228 | Heap-use-after-free in WebCore::SVGImage::drawSVGToImageBuffer | - | 2016-10-02 |
153211 | Heap-use-after-free in webrtc::ThreadPosix::Run | - | 2016-10-02 |
153566 | Heap-use-after-free in WebCore::FontCache::purgeInactiveFontData | - | 2016-10-02 |
153128 | Buffer overrun in Harfbuff | - | 2016-10-02 |
153184 | Heap-use-after-free in WebCore::computeNonFastScrollableRegion | - | 2016-10-02 |
153048 | Invalid pointer read in std::basic_string | - | 2016-10-02 |
152916 | Security: browser process jump to bad address on osx with getUserMedia() and crazyness | - | 2016-10-02 |
152707 | Invalid pointer write in GrGpu::clear | $1,000 | 2016-10-02 |
152921 | Browser crash, navigator.geolocation.watchPosition issue | - | 2016-10-02 |
85102 | Use after free in WebCore::ContainerNode::parserAddChild | $500 | 2016-10-02 |
85041 | Memory Corruption in video decoding | - | 2016-10-02 |
84946 | Merge http://trac.webkit.org/changeset/87959 and http://trac.webkit.org/changeset/87756 for documentloader use after frees | - | 2016-10-02 |
85003 | Parsing issue with -webkit-calc | $1,000 | 2016-10-02 |
84950 | Merge http://trac.webkit.org/changeset/87856 | - | 2016-10-02 |
84885 | ASSERT obj->parentObject() == this in accessibility tree | - | 2016-10-02 |
84919 | Memory corruption in browser process with interstitial that goes back | - | 2016-10-02 |
84805 | Flash/GPU memory corruption in critical section. | $500 | 2016-10-02 |
84797 | Click Reload this page button after Conway's Game of Life starts causes Aw Snap error | - | 2016-10-02 |
84763 | POssible mac use after free in drag & drop code | - | 2016-10-02 |
84933 | Browser crash with IndexedDB and very long database names | - | 2016-10-02 |
84819 | Bad cast in cloning elements with shadow DOM | - | 2016-10-02 |
84597 | use-after-free in WebCore::LevelDBTransaction::commit | - | 2016-10-02 |
84584 | Invalid memory access caused by ThumbnailGenerator | - | 2016-10-02 |
84452 | Bad cast in HTMLMediaElement::mediaControls | $1,000 | 2016-10-02 |
84418 | Shockwave crashed | - | 2016-10-02 |
84402 | Extensions permission elevevation using javascript: in homepage_url | - | 2016-10-02 |
84355 | use-after-free in svg fontfacelement | $1,000 | 2016-10-02 |
84600 | Security: Web page can initiate speech recognition without user knowing about it | - | 2016-10-02 |
84234 | [LangFuzz] Crash @ MarkCompactCollector::SweepSpaces() or SeqTwoByteString::SeqTwoByteStringReadBlockIntoBuffer() (64 bit) | $1,000 | 2016-10-02 |
84160 | Use after free in accessibility notifications. | - | 2016-10-02 |
84016 | Use after free in BrowserAccessibility::DetachTree | - | 2016-10-02 |
84002 | OOB read in ComplexTextController constructor (ComplexTextControllerLinux.cpp) + OOB read in WidthIterator | - | 2016-10-02 |
83917 | OOB Write in Skia Shader Blitter | - | 2016-10-02 |
83903 | Vai | - | 2016-10-02 |
83848 | Use after free in LayerChromium::~LayerChromium | - | 2016-10-02 |
83841 | User information leakage esp local paths, username in webgl getProgramInfoLog | - | 2016-10-02 |
84333 | use after free in WebCore::ContainerNode::firstChild / WebCore::XMLDocumentParser::insertErrorMessageBlock | - | 2016-10-02 |
83672 | Stale layout root set as input element when child of a keygen with autofocus | - | 2016-10-02 |
83598 | OOB read in WebCore::parseColorIntOrPercentage | - | 2016-10-02 |
83275 | UXSS with window.execScript | $3,133 | 2016-10-02 |
83273 | Browser prompt when installing unpacked npapi extensions | - | 2016-10-02 |
83270 | oob read in WebCore::ImageBufferData::getData | - | 2016-10-02 |
83743 | Universal XSS using contentWindow.eval | $1,000 | 2016-10-02 |
83235 | Bad cast in RenderBlock::createLineBoxes due to double attach in htmlformelement | - | 2016-10-02 |
83012 | Use after free in XMLDocumentParser | - | 2016-10-02 |
83010 | An extension can access and modify all chrome:// pages, options, etc. | $1,000 | 2016-10-02 |
82903 | OOB write in BlobURLRequestJob::HeadersCompleted | - | 2016-10-02 |
82873 | Memory corruption in GPU command buffer | - | 2016-10-02 |
83031 | Chrome spoof on 302 redirect | - | 2016-10-02 |
82841 | Browser crash @ closing chrome://settings/syncSetup | - | 2016-10-02 |
82817 | buffer overflow marshalling data from sandbox | - | 2016-10-02 |
82653 | Use after free due to incorrectly setting document.body to non body elements, elements from other docs. | - | 2016-10-02 |
82633 | Bad cast in CSSParser::createFontFaceRule | - | 2016-10-02 |
82597 | document.execCommand('copy') return always false | - | 2016-10-02 |
82552 | REGRESSION (83075): Use after free in line box culling optimization | - | 2016-10-02 |
82546 | Stale pointer in WebCore::RenderBlock::marginBeforeForChild | $1,000 | 2016-10-02 |
82516 | write-after-free in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h:58 | - | 2016-10-02 |
82438 | OOB read in media::FFmpegVideoDecodeEngine::Initialize | - | 2016-10-02 |
82416 | IndexedDB crash on index.getKey | - | 2016-10-02 |
82309 | CRASH @ DownloadItem::UpdateObservers() | - | 2016-10-02 |
82184 | Renderer crash @ GrTHashTable<GrGpuGLShaders::ProgramCache::Entry,GrBinHashKey<GrGpuGLShaders::ProgramCache::Entry,32>,8>::remove(GrBinHashKey<GrGpuGLShaders::ProgramCache::Entry,32> const &,GrGpuGLShaders::ProgramCache::Entry const *) | - | 2016-10-02 |
82161 | Google Chrome (Pwned) | - | 2016-10-02 |
82154 | out-of-bound access in third_party/WebKit/Source/WebKit/chromium/src/WebFrameImpl.cpp | - | 2016-10-02 |
82152 | Need to merge WebKit 64-bit issue http://trac.webkit.org/changeset/86106 | - | 2016-10-02 |
82096 | Merge http://trac.webkit.org/changeset/85693 | - | 2016-10-02 |
82444 | Local file disclosure when pasting stuff from Excel, etc. | - | 2016-10-02 |
82018 | TEST TEST IGNORE | - | 2016-10-02 |
81949 | use-after-free in imageloader with fallbackcontent | $1,000 | 2016-10-02 |
82083 | Google Chrome Pwned by VUPEN aka Sandbox/ASLR/DEP Bypass | - | 2016-10-02 |
161077 | Invalid pointer write in GrRenderTarget::onRelease | $1,000 | 2016-10-02 |
161089 | Indexeddb createIndex() crashes the page | - | 2016-10-02 |
161015 | Heap-use-after-free in WebCore::HTMLConstructionSite::mergeAttributesFromTokenIntoElement | - | 2016-10-02 |
161239 | Heap-use-after-free in WebCore::IDBTransactionBackendImpl::taskTimerFired | - | 2016-10-02 |
160926 | Security:Check for integer wrap in PPB_ImageData_Impl::Init() is insufficient | - | 2016-10-02 |
160480 | Security: Integer overflow in opus_packet_parse_impl | - | 2016-10-02 |
160450 | Heap-buffer-overflow in WebCore::InlineFlowBox::placeBoxRangeInInlineDirection | - | 2016-10-02 |
160380 | Heap-use-after-free in WebKit::ChromePrintContext::spoolPage | - | 2016-10-02 |
160760 | Security: NaCl sandbox escape; missing register check across a superinstruction | - | 2016-10-02 |
160803 | Security: ugly crash with history.replaceState() while the window displays HTTPS interstitial | - | 2016-10-02 |
160456 | Security: Restrict chromoting viewer plugin to chromoting extension | - | 2016-10-02 |
160010 | [LangFuzz] Crash at v8::internal::BasicJsonStringifier::SerializeString | $1,000 | 2016-10-02 |
159829 | Heap-buffer-overflow in WebCore::HTMLInputElement::isImageButton | - | 2016-10-02 |
159828 | Heap-use-after-free in WebCore::RenderLayer::hitTest | - | 2016-10-02 |
159553 | Security: Integer overflow in remoting viewer AudioDecoderSpeex::Decode | - | 2016-10-02 |
159429 | Security: Use after free on ~AssociatedURLLoader with pdf plugin | $1,000 | 2016-10-02 |
159338 | Heap-use-after-free in WebCore::SVGDocumentExtensions::removeAllElementReferencesForTarget | $1,000 | 2016-10-02 |
160068 | Merge http://trac.webkit.org/changeset/133840 | - | 2016-10-02 |
160038 | Security: Unquoted Path vulnerability in GoogleCrashHandler | - | 2016-10-02 |
159165 | Heap-use-after-free in webkit::ppapi::PluginInstance::PrintBegin | - | 2016-10-02 |
159229 | Security: Integer overflow in remoting viewer AudioDecoderOpus::Decode | - | 2016-10-02 |
158992 | Heap-use-after-free in WebCore::RenderTextTrackCue::layout | - | 2016-10-02 |
158898 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
158897 | Heap-buffer-overflow in WebCore::RenderBlock::clone | - | 2016-10-02 |
159219 | Heap-use-after-free in WebCore::EventHandler::handleMousePressEvent | - | 2016-10-02 |
159098 | Heap-buffer-overflow in WebCore::TextTrackCueList::add | - | 2016-10-02 |
158693 | Heap-use-after-free in WebCore::RenderLayerModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
158695 | Heap-use-after-free in WebCore::WidgetHierarchyUpdatesSuspensionScope::moveWidgets | - | 2016-10-02 |
158533 | Heap-use-after-free in WebCore::RenderLayer::paintLayerContents [MathML] | - | 2016-10-02 |
158457 | Heap-use-after-free in non-virtual thunk to content::RenderViewImpl::createPopupMenu | - | 2016-10-02 |
158249 | Security: Heap-buffer-underflow in xmlParseAttValueComplex | - | 2016-10-02 |
158204 | Heap-use-after-free in WebCore::Frame::dispatchVisibilityStateChangeEvent | $1,500 | 2016-10-02 |
158199 | Heap-use-after-free in WebCore::StyleCachedImageSet::cssValue | - | 2016-10-02 |
158707 | Heap-use-after-free in WebCore::RenderObject::isBody | - | 2016-10-02 |
158547 | Heap-use-after-free in WebCore::HTMLInputElement::setValue for type=range, type=date, and type=time with datalist | - | 2016-10-02 |
158060 | Heap-use-after-free in WebCore::CachedResource::checkNotify | - | 2016-10-02 |
157951 | Heap-use-after-free in non-virtual thunk to WebKit::DateTimeChooserImpl::setValueAndClosePopup | - | 2016-10-02 |
157875 | Heap-use-after-free in WebCore::OpenTypeVerticalData::substituteWithVerticalGlyphs | - | 2016-10-02 |
157845 | Heap-use-after-free in skia::BGRAConvolve2D | $500 | 2016-10-02 |
157779 | Heap-use-after-free in WebKit::WebMediaStreamDescriptor::label | - | 2016-10-02 |
157778 | Heap-use-after-free in WebCore::CSSStyleRule::style | - | 2016-10-02 |
157585 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::~BaseMultipleFieldsDateAndTimeInputType | - | 2016-10-02 |
158065 | Stack-buffer-overflow in WebCore::SVGMaskElement::~SVGMaskElement | - | 2016-10-02 |
157463 | Heap-use-after-free in content::LocalVideoCapture::Stop | - | 2016-10-02 |
157516 | Security: XSS auditor can sometimes be used to maliciously alter form action property. | - | 2016-10-02 |
157363 | Heap-buffer-overflow in void std::__final_insertion_sort<WebCore::SMILTimeWithOrigin*> | - | 2016-10-02 |
157289 | Invalid cast in WebCore::toInsertionPoint / WebCore::ContentDistributor::distribute | - | 2016-10-02 |
157462 | Heap-use-after-free in webrtc::MediaStreamSignaling::UpdateRemoteStreams | - | 2016-10-02 |
157079 | Security: Integer overflow in libwebp "ParseOptionalChunks" allows memory disclosure | $3,500 | 2016-10-02 |
157071 | Heap-use-after-free in non-virtual thunk to WebKit::DateTimeChooserImpl::setValueAndClosePopup | - | 2016-10-02 |
157019 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
157124 | UNKNOWN in v8::internal::ObjectHashTable::Put | - | 2016-10-02 |
157053 | Heap-use-after-free in WebCore::Element::attributeChanged | - | 2016-10-02 |
156977 | Heap-use-after-free in WebCore::RenderText::removeAndDestroyTextBoxes | - | 2016-10-02 |
156980 | Security: workers can initialize the sandbox multithreaded | - | 2016-10-02 |
157009 | Heap-use-after-free in WebCore::SubresourceLoader::willSendRequest | - | 2016-10-02 |
81947 | Use after free in WebCore::requiresLineBox | - | 2016-10-02 |
81753 | Valgrind reports issues in icu_46::RegexMatcher | - | 2016-10-02 |
81916 | Stale observer in BrowsingDataRemover's observer_list_ | $500 | 2016-10-02 |
81351 | CSSSelector double frees | - | 2016-10-02 |
81348 | Use after free when removing elements with reflections | - | 2016-10-02 |
81307 | Security: dropping file:/// URLs into gmail grants access to files | - | 2016-10-02 |
81803 | out-of-bounds use in SkBitmapOperations::CreateMaskedBitmap | - | 2016-10-02 |
81681 | Memory corruption in GraphicsContext::fillPath | - | 2016-10-02 |
80680 | Security: .keystone_install_lock is insecurely handled in install.py | - | 2016-10-02 |
80608 | Multiple integer overflows in SVG filter effects | - | 2016-10-02 |
80401 | Url bar spoof using onbeforeunload when user cancels navigation | - | 2016-10-02 |
80358 | WebCore::InspectorBackendDispatcher::Runtime_evaluate user after free | - | 2016-10-02 |
81234 | Flash content vulnerability | - | 2016-10-02 |
80255 | use after free in WebCore::RenderSVGInlineText::characterStartsNewTextChunk | - | 2016-10-02 |
80222 | Herror of chrome | - | 2016-10-02 |
80287 | Regression(81992): Stale node set as layout root | - | 2016-10-02 |
80116 | Stale pointer in WebCore::Document::recalcStyleSelector | - | 2016-10-02 |
79746 | Floats not cleared due to overflow (remaining usecase) | $1,000 | 2016-10-02 |
79726 | BrowserAccessibility browser process memory corruption | - | 2016-10-02 |
79668 | invalid read w/new skia update | - | 2016-10-02 |
79661 | Sandbox is broken (low integrity level) | - | 2016-10-02 |
79595 | Bad cast due to childrenInline assumption in RenderSVGText | - | 2016-10-02 |
79566 | Bypass extensions permission | $500 | 2016-10-02 |
79862 | Bypass extensions permission app launch web_url should not allow javascript: chrome: | - | 2016-10-02 |
79452 | H | - | 2016-10-02 |
79426 | HTTP Basic Auth Realm Spoof | - | 2016-10-02 |
79371 | Use after free in ImplicitAnimation::~ImplicitAnimation | - | 2016-10-02 |
79362 | Reproducible PDF crash (siryo3.pdf) | - | 2016-10-02 |
79266 | Bypass unsafe file types dialog | - | 2016-10-02 |
79075 | Stale node set as layout root, due to one caption not laid out in table with two captions | - | 2016-10-02 |
79055 | Freed m_viewportRenderer in FrameView::updateOverflowStatus | - | 2016-10-02 |
79025 | Use after free when inline runin precedes details tag | - | 2016-10-02 |
78948 | Integer underflow in HTMLFormElement::m_associatedElementsAfterIndex | - | 2016-10-02 |
78861 | Memory corruption in RenderViewHost related to observers code | - | 2016-10-02 |
78842 | proslor.co.be | - | 2016-10-02 |
78841 | invalid access with bad html | $1,000 | 2016-10-02 |
78798 | Security: XSS in dev tools HTML inspector | - | 2016-10-02 |
78639 | Memory corruption leading to OOB read symptom in PDF initialization | $1,000 | 2016-10-02 |
78576 | compareDocumentPosition memory corruption | - | 2016-10-02 |
78575 | Bad cast in reverseInlineBoxRangeAndValueListsIfNeeded | - | 2016-10-02 |
78572 | CounterNode memory corruption | - | 2016-10-02 |
78558 | chrome bug | - | 2016-10-02 |
78524 | ANGLE buffer overflow | $1,000 | 2016-10-02 |
78516 | Looks like a stale frame in UserScriptSlave::InjectScripts | - | 2016-10-02 |
78427 | url spoof through bookmark bar click | - | 2016-10-02 |
78401 | Stale node being set as layout root | - | 2016-10-02 |
78327 | Integer overflow in FilterEffect::copyImageBytes | - | 2016-10-02 |
78296 | False warning of Google Chrome / Fake Antimalware Tool | - | 2016-10-02 |
78270 | [LangFuzz] V8: Crash in HeapObject::map_word on GC | $1,000 | 2016-10-02 |
78559 | chrome bug | - | 2016-10-02 |
78106 | ZDI-CAN-1108: WebKit ContentEditable Inline Style Remote Code Execution | - | 2016-10-02 |
78071 | css parsing issue in calc | $1,000 | 2016-10-02 |
78038 | ThreadSanitizer reports a potential use after free in net::X509Certificate::Verify | - | 2016-10-02 |
78031 | Url bar spoof | $1,000 | 2016-10-02 |
78145 | Invalid write in SVGTextLayoutEngine | - | 2016-10-02 |
78053 | Stale m_fontList in svgFontAndFontFaceElementForFontData | - | 2016-10-02 |
165747 | IPC: renderer out-of-bounds crash creating 3D context from malformed PPAPI message | - | 2016-10-02 |
165836 | Information leak when sending messages cross process that use WriteData() on structures/objects which contain padding bytes. | - | 2016-10-02 |
165549 | Security: Sandbox isolation not working | - | 2016-10-02 |
165602 | Heap-use-after-free in WebCore::CSSStyleRule::style | - | 2016-10-02 |
165804 | Security: SnapshotProvider exposed to other applications on the device | - | 2016-10-02 |
165601 | Heap-use-after-free in matroska_parse_block | - | 2016-10-02 |
165456 | Heap-use-after-free in WebCore::Element::hasPendingResources | - | 2016-10-02 |
165430 | Heap-buffer-overflow in media::AudioRendererAlgorithm::OutputFasterPlayback | - | 2016-10-02 |
165102 | Security: devtool xss | - | 2016-10-02 |
165091 | Bypassing Chrome's XSS filter, XSSAuditor | - | 2016-10-02 |
165537 | PDF: off-by-one read when scanning for startxref | - | 2016-10-02 |
165538 | PDF: integer overflows in JS array handling | - | 2016-10-02 |
165432 | Use after free in SVG path | $500 | 2016-10-02 |
164958 | IPC: PPAPI messages have problems with use of signed integers for lengths | - | 2016-10-02 |
165015 | Heap-use-after-free in WebCore::Element::normalizeAttributes | $1,000 | 2016-10-02 |
164701 | PDF: regressions due to merge losing previous security fixes | - | 2016-10-02 |
164697 | PDF: regressions in JBIG2 codec | - | 2016-10-02 |
164682 | Input validation error in BrowserPluginEmbedderHelper::OnHandleInputEvent() leads to bad cast | - | 2016-10-02 |
164643 | Security: ASan reports a use-after-free while using SecureShell | - | 2016-10-02 |
165009 | Heap-use-after-free in WebCore::SVGSMILElement::disconnectConditions | - | 2016-10-02 |
164946 | IPC: GPU messages have integer truncation (bad use of size_t) and integer sign extension (bad use of signed type) issues | - | 2016-10-02 |
164582 | Heap-buffer-overflow in SkRectClipBlitter::blitAntiH | - | 2016-10-02 |
164581 | Heap-use-after-free in WebCore::TextTrackCue::isActive | - | 2016-10-02 |
164565 | Security: V8 bug may give out-of-bounds access to the stack | - | 2016-10-02 |
164490 | IPC: integer overflow in Windows' SharedMemory::Create | - | 2016-10-02 |
164454 | switch off mathml for m24 | - | 2016-10-02 |
164263 | Heap-use-after-free in WebCore::FrameSelection::directionOfSelection | - | 2016-10-02 |
164584 | Translate should load resources over HTTPS even if the original page is loaded via HTTP. | - | 2016-10-02 |
163593 | Heap-use-after-free in WebCore::RenderBlock::finishDelayUpdateScrollInfo [MathML] | - | 2016-10-02 |
163588 | IPC::Channel::ChannelImpl::ProcessOutgoingMessages - crash | - | 2016-10-02 |
163291 | Heap-buffer-overflow in WebCore::RenderGrid::layoutGridItems | - | 2016-10-02 |
163238 | Security: XSS in bug tracker? <script>alert(0)</script> again? | - | 2016-10-02 |
163218 | Heap-use-after-free in webkit_glue::WebURLLoaderImpl::Context::OnReceivedResponse | - | 2016-10-02 |
163994 | Heap-use-after-free in WebCore::CachedResource::checkNotify | - | 2016-10-02 |
163203 | IndexedDB: Assert hit in IDBObjectStoreBackendImpl::setIndexesReady | - | 2016-10-02 |
162896 | Out of bounds read in WTF::String::String / WebCore::WebVTTParser::constructTreeFromToken | - | 2016-10-02 |
163208 | Security: Workers don't initialize a sandbox on Mac | - | 2016-10-02 |
162835 | Heap-use-after-free in WebCore::MediaPlayer::sourceSetTimestampOffset [exploitable] | $7,331 | 2016-10-02 |
162778 | PDF: use-after-frees in field name tree again | - | 2016-10-02 |
162776 | PDF: out-of-bounds reads with crazy bits per component / num components values | - | 2016-10-02 |
163110 | Heap-use-after-free in WebCore::ApplyStyleCommand::pushDownInlineStyleAroundNode | - | 2016-10-02 |
162620 | Heap-use-after-free in WebCore::RenderSVGResourcePattern::applyResource | - | 2016-10-02 |
162551 | Access violation write in _VEC_memcpy | $1,000 | 2016-10-02 |
162489 | Security: Small info leak in the SUID sandbox helper? | - | 2016-10-02 |
162156 | PDF: more out-of-bounds reads with mismatched colorspaces | - | 2016-10-02 |
162622 | Heap-use-after-free in WebCore::RenderBlock::willBeDestroyed | - | 2016-10-02 |
162494 | Heap-use-after-free in WebCore::PopStateEvent::~PopStateEvent | $1,000 | 2016-10-02 |
162114 | Security: Renderer sandbox bypass by crafting LevelDB database in "profile/File System/" | - | 2016-10-02 |
162115 | Heap-buffer-overflow in SkA8_Blitter::blitH | - | 2016-10-02 |
162032 | Heap-use-after-free in udat_close_46 | - | 2016-10-02 |
161836 | Security: Possible directory traversal vulnerability in ExtensionResource::GetFilePath(). | - | 2016-10-02 |
161690 | Heap-use-after-free in WebCore::RenderSVGResourceContainer::markClientForInvalidation | - | 2016-10-02 |
161662 | Heap-use-after-free in media::BlockingUrlProtocol::SignalReadCompleted | - | 2016-10-02 |
162153 | PDF: bad cast if root page is not a dictionary object | - | 2016-10-02 |
162066 | LOGFONT IPC deserializer doesn't require NULL terminated lfFaceName | - | 2016-10-02 |
161564 | Security: Renderer sandbox bypass on ChildProcessSecurityPolicyImpl::SecurityState::HasPermissionsForFile() | - | 2016-10-02 |
161484 | UNKNOWN in WebCore::RenderObject::propagateStyleToAnonymousChildren | - | 2016-10-02 |
161478 | Heap-buffer-overflow in WebCore::Biquad::process | - | 2016-10-02 |
161458 | Heap-buffer-overflow in apply_kernel_interp | - | 2016-10-02 |
161420 | Heap-buffer-overflow in WTF::StringImpl::create | - | 2016-10-02 |
161639 | Security: ffmpeg oob write4 (222) | $2,000 | 2016-10-02 |
161340 | Security: GPU sandbox is always disabled because of watchdog thread on Linux | - | 2016-10-02 |
161240 | Heap-use-after-free in WebCore::AccessibilityRenderObject::remoteSVGRootElement | - | 2016-10-02 |
77633 | write-after-free in v8::internal::RegExpMacroAssemblerX64::~RegExpMacroAssemblerX64 | - | 2016-10-02 |
77917 | Looks like a bad cast in RenderInputSpeech::paintInputFieldSpeechButton | - | 2016-10-02 |
77786 | URL Bar Spoofing using redirection and location.reload(); | $500 | 2016-10-02 |
77765 | 12 bad cast in editing code relating to htmlelement conversions, isprimitivevalue problems. | - | 2016-10-02 |
77703 | Use-after-free in WebCore::isDeletableElement | - | 2016-10-02 |
77700 | Captured an attack used against Chrome on many google image links, uses chromes own error template against itself | - | 2016-10-02 |
77690 | Use after free in WebCore::ContainerNode::insertedIntoDocument / WebCore::SVGElement::insertedIntoDocument | - | 2016-10-02 |
77940 | ZDI-CAN-1021: Apple Safari Webkit SVG Marker Remote Code Execution Vulnerability | - | 2016-10-02 |
77812 | Security: Chrome Security Pop-up | - | 2016-10-02 |
77669 | Bad cast in WebCore::BreakBlockquoteCommand::doApply | - | 2016-10-02 |
77507 | URL Bar Spoof | $1,000 | 2016-10-02 |
77493 | OOB read with Flash | $1,000 | 2016-10-02 |
77349 | When object destroyed, its select file dialog is not informed to cleared its listener which can call back that destroyed object | - | 2016-10-02 |
77346 | Use After Free in Websockets - possible remote code execution within sandbox | $1,000 | 2016-10-02 |
77181 | OOB function pointer array call FEComponentTransfer::apply | - | 2016-10-02 |
77130 | stale entries in gPercentHeightDescendantsMap | $1,000 | 2016-10-02 |
77053 | Bad cast in HTMLTreeBuilder with closed </form> tags | - | 2016-10-02 |
77038 | repair | - | 2016-10-02 |
77026 | Bypass extension manifest permission | $1,337 | 2016-10-02 |
76966 | RIP goes to zero with select tag, and form validation message with position:relative | $1,000 | 2016-10-02 |
76955 | Renderer crash when visiting http://runescape.wikia.com/wiki/Special:Search | - | 2016-10-02 |
76784 | Bad cast to RenderBlock in accessibility assuming that anonymous blocks are renderblocks. | - | 2016-10-02 |
76771 | use after free in WebCore::ScriptWrappable::wrapper | - | 2016-10-02 |
76666 | URL bar spoof | $1,000 | 2016-10-02 |
76646 | OOB read in FEDisplacementMap::apply | - | 2016-10-02 |
76589 | Crash@ anonymous namespace'::PureCall() when navigate to previous page while speech input API fetching result text | - | 2016-10-02 |
76542 | Linux setuid sandbox allows local privilege escalation | $500 | 2016-10-02 |
76474 | crash in WebKit::WebPluginContainerImpl::handleEvent() | - | 2016-10-02 |
76202 | DownloadThrottlingResourceHandler::OnResponseCompleted NOTREACHED() | - | 2016-10-02 |
76198 | Bad cast in HTMLTreeBuilder::processStartTag | - | 2016-10-02 |
76528 | use after free in AnimationBase::next / AnimationControllerPrivate::styleAvailable | - | 2016-10-02 |
76194 | bad cast in WebCore::toRenderBoxModelObject / WebCore::RenderMathMLRoot::layout | - | 2016-10-02 |
76059 | WebCore::LayerTilerChromium::invalidateRect() - crash | $1,000 | 2016-10-02 |
76031 | Crash when visiting http://kikafriends.forumcommunity.net/ | - | 2016-10-02 |
76029 | Crash in webcore::rendertable::cellafter when visiting http://broadband.biglobe.ne.jp/ | - | 2016-10-02 |
76027 | securiti | - | 2016-10-02 |
76018 | Crash in network stack when running http/tests/loading/redirect-methods.html | - | 2016-10-02 |
76195 | potential bad cast in WebCore::toRenderCombineText/WebCore::RenderBlock::computeInlinePreferredLogicalWidths | - | 2016-10-02 |
76034 | Security:Instant hard-crash with JS code | - | 2016-10-02 |
75821 | Should we reconsider the no-client-UI decision for the web store? | - | 2016-10-02 |
75712 | Integer overflow in style elements | $1,337 | 2016-10-02 |
76001 | Stale pointer in WebCore::LayerRendererChromium::drawLayer | $1,000 | 2016-10-02 |
75835 | use of freed pointer in WebCore::RenderCounter::originalText() | - | 2016-10-02 |
75696 | Security: pushState() should be available only for origin-bearing schemes | - | 2016-10-02 |
75496 | chrome.dll!BrowserAccessibility..InternalReleaseReference ExecAV@NULL (cc7203fb809bd98728cf74b908e66edf) | - | 2016-10-02 |
75629 | Use after free in gpu::gles2::ShaderTranslator | - | 2016-10-02 |
75643 | CSS visited history disclosure | - | 2016-10-02 |
75436 | Detach Geolocation from Frame when Page destroyed. | - | 2016-10-02 |
75560 | Security: address bar updates not synchronized with document transitions | - | 2016-10-02 |
75186 | (WebCore::RenderObjectChildList::destroyLeftoverChildren) Use-after-free with nesting ruby tag and css propierties | $1,000 | 2016-10-02 |
75210 | Harfbuzz segfault in GPOS_Do_Glyph_Lookup | - | 2016-10-02 |
75021 | Use-after-free in InfoBar since ~r76800 | - | 2016-10-02 |
75311 | Bad cast in HTMLTreeBuilder::processStartTag | - | 2016-10-02 |
75347 | Bad cast to RenderBlock with floating select element with required attribute | $500 | 2016-10-02 |
75155 | Integer overflow in WebCore::GraphicsContext::fillRect (Mac) | - | 2016-10-02 |
75070 | Security: do not ignore type= on <object> | - | 2016-10-02 |
75374 | REGRESSION (r80320): Bad cast assertion failure when processing mis-nested foreign content. | - | 2016-10-02 |
74678 | v8 fuzzing - 1175 - use after free | $1,000 | 2016-10-02 |
74763 | Security: Domui process can be ptraced from a compromised renderer leading to sandbox escape | - | 2016-10-02 |
74887 | memcpy from TexSubImage2D causes memory corruption | - | 2016-10-02 |
74891 | chrome://appcache-internals/ xss | - | 2016-10-02 |
74720 | Read uninitialized value from JavaScript. | - | 2016-10-02 |
74677 | v8 fuzzing - 1160 - bad cast of object to string in array join | - | 2016-10-02 |
169685 | Missing validation of webkit_base::DataElement across IPC | - | 2016-10-02 |
169672 | Heap-buffer-overflow in WTF::AtomicString::add | - | 2016-10-02 |
169632 | Security: extensions can silently gain file: host permissions via permissions API | - | 2016-10-02 |
74675 | v8 fuzzing - 1146 - invalid memory access | $1,000 | 2016-10-02 |
74673 | v8 fuzzing - 1166 - exploitable write | $1,000 | 2016-10-02 |
74672 | v8 fuzzing - 1138 - use after free | $1,000 | 2016-10-02 |
74671 | v8 fuzzing - 1136 - corrupt JIT code | $1,000 | 2016-10-02 |
169247 | Attempting free in content::PeerConnectionTracker::UnregisterPeerConnection | - | 2016-10-02 |
169156 | Security: Use after free in FlingAnimatorImplAndroid - writing value to this after this is deleted | - | 2016-10-02 |
169054 | Security: memory corruption with webgl on linux intel driver | $3,133 | 2016-10-02 |
169295 | IPC: bad pointer used in browser if renderer sends mismatched vector lengths | - | 2016-10-02 |
169398 | Heap-use-after-free in WebCore::RenderBlock::willBeDestroyed | - | 2016-10-02 |
169401 | Security: JavaScript injection into arbitrary web pages via Intent with JavaScript URI | $500 | 2016-10-02 |
168968 | Heap-use-after-free in DownloadRequestInfoBarDelegate::~DownloadRequestInfoBarDelegate | - | 2016-10-02 |
169006 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
168768 | Heap-use-after-free in WebKit::WebMediaPlayerClientImpl::AudioSourceProviderImpl::setClient | $1,000 | 2016-10-02 |
168710 | IPC: avoid operator-new based integer overflow in Flash menu deserialization | - | 2016-10-02 |
168982 | Heap-use-after-free in WebCore::SVGAnimateMotionElement::updateAnimationPath | - | 2016-10-02 |
168969 | Heap-use-after-free in WebCore::Element::hasPendingResources | - | 2016-10-02 |
168780 | Heap-use-after-free in WebCore::RenderObject::willBeRemovedFromTree | - | 2016-10-02 |
168473 | Heap-buffer-overflow in vorbis_floor0_decode | - | 2016-10-02 |
168570 | Crashing in webkit_media::WebMediaPlayerMS::putCurrentFrame(WebKit::WebVideoFrame *) | - | 2016-10-02 |
168489 | Heap-use-after-free in WebCore::AccessibilityNodeObject::document | - | 2016-10-02 |
168442 | Security: Non-privileged extensions can monitor browsing activity via chrome.tabs.onUpdated events | - | 2016-10-02 |
167840 | Linux sandbox bypass in file_util_posix.cc CopyDirectory() | - | 2016-10-02 |
167788 | Security: heap-buffer-overflow on GetImageRepToPaint. | - | 2016-10-02 |
167780 | Heap-use-after-free in bool WebCore::SelectorChecker::checkOneSelector<WebCore::DOMSiblingTraversalStrategy> | - | 2016-10-02 |
167868 | Heap-use-after-free in WebCore::Document::updateHoverActiveState | - | 2016-10-02 |
168050 | Attacker controlled size mismatch in WidgetDidReceivePaintAtSizeAck() | - | 2016-10-02 |
167827 | Heap-use-after-free in WebCore::Element::cloneElementWithoutChildren | - | 2016-10-02 |
167924 | Heap-use-after-free in WebCore::RenderLayerModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
167498 | Heap-use-after-free in WebCore::CSSStyleRule::style | - | 2016-10-02 |
167443 | Heap-buffer-overflow in WebCore::FontCache::releaseFontData | - | 2016-10-02 |
167412 | IPC: GPU message OnMsgAssignPictureBuffers incorrectly assumed same-sized vectors | - | 2016-10-02 |
167728 | Heap-use-after-free in WebCore::SVGTransformListV8Internal::numberOfItemsAttrGetter | - | 2016-10-02 |
167607 | Security: Failure to enforce key usage | - | 2016-10-02 |
167572 | Heap-use-after-free in WebCore::HTMLConstructionSite::mergeAttributesFromTokenIntoElement | - | 2016-10-02 |
167147 | Heap-use-after-free in WebCore::Document::implicitClose | - | 2016-10-02 |
167122 | HyphenatorHostMsg_OpenDictionary IPC allows arbitrary file reads from a compromised renderer | - | 2016-10-02 |
167110 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
167069 | Heap-buffer-overflow in matroska_parse_block | $500 | 2016-10-02 |
166916 | Security: mixed content XHR doesn't trigger mixed content warnings | - | 2016-10-02 |
166867 | Security: ReferencesParent bypass with a 0x00 byte | - | 2016-10-02 |
166795 | Harden audio stream creation in the browser | - | 2016-10-02 |
167180 | Security: NaCl ARM validator sandbox escape, Chrome M25 | - | 2016-10-02 |
167311 | Heap-use-after-free in WebCore::GenericEventQueue::enqueueEvent | - | 2016-10-02 |
167218 | Arbitrary server response with Content-Encoding including sdch can cause crashes if sdch is not configured | - | 2016-10-02 |
166621 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
166565 | Heap-buffer-overflow in media::AudioBus::FromInterleavedPartial | - | 2016-10-02 |
166554 | [LangFuzz] Crash at v8::internal::Deoptimizer::DoComputeOutputFrames with invalid read | $1,000 | 2016-10-02 |
166553 | [LangFuzz] Crash at v8::internal::HeapObject::SizeFromMap with invalid read | $1,000 | 2016-10-02 |
166523 | [Mac] apprtc crashes when output sampling rate set to 96000 Hz | - | 2016-10-02 |
166513 | Heap-use-after-free in WebCore::StyledElement::ensureMutableInlineStyle | - | 2016-10-02 |
166503 | audio getUserMedia call crashes tab when input sampled at 88200 Hz | - | 2016-10-02 |
166708 | BrowserPluginGuest blindly trusts the size of shared memory regions leading to overflow | - | 2016-10-02 |
166627 | Heap-use-after-free in WebCore::Prerender::didStartPrerender | - | 2016-10-02 |
166324 | Heap-use-after-free in WebCore::RenderBlock::insertIntoTrackedRendererMaps | - | 2016-10-02 |
166336 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
166271 | PDF: use-after-free in colorspace cache | - | 2016-10-02 |
166257 | Security: ChromeBrowserSyncAdapterService is exported, but does not need to be? | - | 2016-10-02 |
165928 | Heap-use-after-free in WebCore::SVGSMILElement::isSMILElement | - | 2016-10-02 |
166493 | IPC: missing integer checks on Pepper UDP socket handling | - | 2016-10-02 |
166306 | WebCore::SMILTimeContainer::updateAnimations - crash | - | 2016-10-02 |
165926 | Heap-use-after-free in WTF::Vector<WTF::RefPtr<WebCore::Node>, 0ul>::shrinkCapacity | - | 2016-10-02 |
165864 | Heap-use-after-free in WebCore::ChildNodeInsertionNotifier::notifyDescendantInsertedIntoDocument | $1,000 | 2016-10-02 |
74665 | v8 fuzzing - 1109 (out of bounds write) | $1,000 | 2016-10-02 |
74662 | v8 fuzzing - 1108 potential use-after-free in RegExp code | $1,000 | 2016-10-02 |
74660 | v8 fuzzing - 1174 - out-of-bounds write in reloc info | $1,000 | 2016-10-02 |
74653 | bypass SOP with blob: | $1,000 | 2016-10-02 |
74669 | v8 fuzzing - 1113 - stack corruption | $1,000 | 2016-10-02 |
74670 | v8 fuzzing 1128 - out of bounds write | $500 | 2016-10-02 |
74666 | v8 fuzzing 1122 - stack corruption | $1,000 | 2016-10-02 |
74372 | chrome://blob-internals/ xss | - | 2016-10-02 |
73962 | use after free due to floats not cleared (overflow) | $1,000 | 2016-10-02 |
74585 | Crash in CookieMonster DeleteAnyEquivalentCookie. | - | 2016-10-02 |
74650 | Placeholder bug for v8 security issues affecting Chrome 9 | - | 2016-10-02 |
74649 | OOB read in SearchBuffer::append | - | 2016-10-02 |
74348 | Regression: Stale node set as layout root (issue in Canvas parent layout) | - | 2016-10-02 |
73887 | GMail renderer crash @ MessageLoop::PostTask_Helper(tracked_objects::Location const &,Task *,__int64,bool) | - | 2016-10-02 |
73716 | Leak of address of heap object via xslt generate-id() function | - | 2016-10-02 |
73932 | Bad cast to text node in CompositeEditCommand::breakOutOfEmptyMailBlockquotedParagraph | - | 2016-10-02 |
73899 | Regression: Crash in RenderCombineText::combineText when running fast/text/international/text-combine-parser-test.html on Windows with full page heap enabled | - | 2016-10-02 |
73893 | Chrome:+Crash+Report+-+Stack+Signature:+`anonymous+namespace'::PureCall()-0ba6cf43_1414c783_9939c740_d9e6ed78_7be33815 | - | 2016-10-02 |
73235 | Stale pointer in WebCore::RenderBlock::lowestPosition | $1,000 | 2016-10-02 |
73216 | Use after free of frame loader in DocumentLoader::commitLoad | $1,000 | 2016-10-02 |
73526 | Floats not cleared to logical height wraps. | $1,000 | 2016-10-02 |
73478 | Pages can continuously poll the OS clipboard for paste data | - | 2016-10-02 |
73338 | Regression: stack buffer overflow in utf8 converter | - | 2016-10-02 |
73001 | Use-after-free in ObserverListBase / TabContents | - | 2016-10-02 |
73026 | dereference poisoned value in avcodec_52!ff_thread_decode_frame | - | 2016-10-02 |
72910 | Browser crash/segfault when selecting very long option in select | - | 2016-10-02 |
72908 | Freed timer heap element used | - | 2016-10-02 |
72832 | Reliability issues with WebCore::RenderBlock due to use after free in floats | - | 2016-10-02 |
73134 | Crash due to bad cast to rendertextfragment in updatefirstletter. | $1,000 | 2016-10-02 |
73163 | Heap corruption in safe_browsing detected on the Valgrind bot (might be fixed by SQLITE ROLL ??) | - | 2016-10-02 |
72936 | Freed scrollbar in ScrollView::updateScrollbars | - | 2016-10-02 |
72492 | Cross application unsafe redirect | $1,000 | 2016-10-02 |
72437 | Crash in ContainerNodeAlgorithms.h with outdated ice-tea plugin | $1,000 | 2016-10-02 |
72434 | stale pointer, invalid read, svg | - | 2016-10-02 |
72523 | chrome.tabs.captureVisibleTab allows capturing images of any "file://" resource | - | 2016-10-02 |
72517 | Dev. console null character crash @ history::URLDatabase::GetMostRecentKeywordSearchTerms | $500 | 2016-10-02 |
72399 | Valgrind reports on JPEG decoding since r74103 | - | 2016-10-02 |
72340 | use after free in WebCore::RenderCounter::destroyCounterNode | $1,000 | 2016-10-02 |
72189 | Bypass popup blocker using custom event and onMouseOver | - | 2016-10-02 |
72135 | IDBTransaction and IDBRequest can be deleted while ScriptExecutionContext is iterating | - | 2016-10-02 |
72134 | Potential buffer overrun in SVGTextRunWalker::walk() | - | 2016-10-02 |
72028 | Stale continuation flow pointer for ContinuationOutlineTableMap | $1,000 | 2016-10-02 |
71960 | OOB Read in WebGL due to integer overflows | - | 2016-10-02 |
72387 | Out of bounds read in WebCore::LayerTilerChromium::invalidateRect (dev only) | $1,000 | 2016-10-02 |
72217 | HTMLFormElement::formElementIndex() returns a bad index into a vector of form associated elements | - | 2016-10-02 |
71786 | ThreadSanitizer reports a race on WebCore::schemesWithUniqueOrigins (on cross_fuzz) | - | 2016-10-02 |
71734 | Security: accessing DataView methods with negative index could cause crash | - | 2016-10-02 |
71717 | webgl causes segfault | - | 2016-10-02 |
71601 | Switch to https by default in autofill toolbar server queries | - | 2016-10-02 |
71788 | Memory corruption playing back specially crafted .ogg vorbis file. | - | 2016-10-02 |
71763 | use-after-free when document.close and document.write are called after requesting a non-existing script | $1,000 | 2016-10-02 |
71855 | stale pointer in WebCore::RenderBlock::insertFloatingObject | $1,000 | 2016-10-02 |
71545 | Chrome_Mac: Crash Report - Stack Signature: WebKit::NotificationPresenterImpl::checkPermission-5428423 | - | 2016-10-02 |
71388 | Security:WebCore::HTMLTextAreaElement::updateValue+0xf | $1,000 | 2016-10-02 |
71386 | Stale nodes in Document::recalcStyleSelector | $1,000 | 2016-10-02 |
71370 | https not properly connected to google doc and gmail. | - | 2016-10-02 |
71357 | PPAPI var objects reference invalid memory when the instance is deleted | - | 2016-10-02 |
71586 | race in base/third_party/xdg_mime (crasher) | $500 | 2016-10-02 |
71296 | Stale iterator in SVGDocumentExtensions::startAnimations() | $1,000 | 2016-10-02 |
71551 | Cross_fuzz and ClusterFuzz crashes in WebCore::DatabaseTracker::removeOpenDatabase | - | 2016-10-02 |
71345 | fail to connect with https when browsing google doc in chrome | - | 2016-10-02 |
71203 | Branch ANGLE and merge fixes to m9 | - | 2016-10-02 |
173654 | Heap-use-after-free in WebCore::FrameSelection::notifyRendererOfSelectionChange | - | 2016-10-02 |
173500 | XSS: chromiumbugs.appspot.com | - | 2016-10-02 |
173483 | New search UI (1993) could lead to self-XSS | $500 | 2016-10-02 |
173402 | ASSERTION FAILED: !object || object->isRenderImage(), UNKNOWN in WebCore::HTMLAnchorElement::handleClick | - | 2016-10-02 |
173399 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::RenderListItem::positionListMarker | - | 2016-10-02 |
173397 | Heap-buffer-overflow in WTF::MemoryInstrumentation::Wrapper<WebCore::ContainerNode>::callReportMemoryUsage | - | 2016-10-02 |
173341 | Heap-use-after-free in content::PeerConnectionTracker::TrackSetSessionDescription | - | 2016-10-02 |
173250 | Security: Heap-Buffer-Overflow in extensions::SetIconNatives | - | 2016-10-02 |
173050 | Heap-use-after-free in WebCore::Node::removedLastRef | - | 2016-10-02 |
173049 | Heap-use-after-free in WebKit::WebLayerImpl::layer | - | 2016-10-02 |
172993 | Heap-use-after-free in WebCore::ScrollingCoordinator::hasVisibleSlowRepaintViewportConstrainedObjects | - | 2016-10-02 |
173068 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderFrameSet::paint | - | 2016-10-02 |
172926 | Heap-buffer-overflow in WebCore::AudioBufferSourceNode::process | $1,000 | 2016-10-02 |
172918 | Flash shouldn't load if the "src" URL has a bad content type and Content-Type-Options: nosniff | - | 2016-10-02 |
172824 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::commonTreeScope | - | 2016-10-02 |
172822 | ASSERTION FAILED: !object || object->isTextControl(), UNKNOWN in WebCore::TextControlInnerTextElement::customStyleForRenderer | - | 2016-10-02 |
172984 | Any MITM attacker can load NaCl :-( | - | 2016-10-02 |
172814 | Heap-use-after-free in WebCore::RenderTextTrackCue::layout | - | 2016-10-02 |
172658 | Security: TLS timing attack leading to message recovery | - | 2016-10-02 |
172573 | Compromised renderer can load banned plug-in | - | 2016-10-02 |
172342 | Heap-use-after-free in WebCore::AudioNodeInput::updateInternalBus | $1,000 | 2016-10-02 |
172331 | Use-after-free in WebCore::VectorMath::vsmul | $1,000 | 2016-10-02 |
172794 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
172243 | Heap-buffer-overflow in WebCore::OscillatorNode::process | $1,000 | 2016-10-02 |
172119 | Security: Do not allow Chrome Web Store URLs to commit in unprivileged processes | - | 2016-10-02 |
171962 | UNKNOWN in _wordcopy_fwd_aligned | - | 2016-10-02 |
171951 | Security: UAF in WebCore::SecurityOrigin::databaseIdentifier() | $1,500 | 2016-10-02 |
172264 | DatabaseMessageFilter: path traversal in origin_identifier | - | 2016-10-02 |
172071 | verify svn.golo.chromium.org subversion package is up-to-date with security fixes | - | 2016-10-02 |
171557 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::toRenderBox | - | 2016-10-02 |
171392 | Cross-Origin copy&paste / drag&drop allowing XSS (again, this time srcdoc) | - | 2016-10-02 |
171630 | ASSERTION FAILED: document() == newChild->document(), UNKNOWN in WebCore::ContainerNode::parserAppendChild | - | 2016-10-02 |
171569 | Security: Escape from NaCl sandbox on Mac OS X due to signal handler without SA_ONSTACK | - | 2016-10-02 |
170715 | SIGSEGV in NotificationUIManagerImpl::CancelAllBySourceOrigin() | - | 2016-10-02 |
171130 | Heap-use-after-free in WebCore::AXObjectCache::notificationPostTimerFired | - | 2016-10-02 |
170666 | Heap-use-after-free in SkAlphaRuns::add | - | 2016-10-02 |
171131 | Heap-use-after-free in WebCore::AccessibilityRenderObject::remoteSVGRootElement | - | 2016-10-02 |
170683 | Heap-use-after-free in ChromeURLDataManagerBackend::StartRequest | - | 2016-10-02 |
171134 | XSS in 1993 history handling | $500 | 2016-10-02 |
170679 | Heap-buffer-overflow in WebCore::RenderBlock::clone | - | 2016-10-02 |
170199 | Heap-use-after-free in WebCore::HTMLSelectElement::length | - | 2016-10-02 |
170240 | Heap-use-after-free in WebCore::LiveNodeListBase::invalidateCache | - | 2016-10-02 |
170360 | Use-after-free: Merge http://trac.webkit.org/changeset/139732 | - | 2016-10-02 |
170432 | UNKNOWN in WTF::equalIgnoringCase | - | 2016-10-02 |
170237 | Heap-use-after-free in WebCore::InspectorInstrumentation::didHandleEventImpl | - | 2016-10-02 |
170188 | Heap-use-after-free in WebCore::Document::updateHoverActiveState | - | 2016-10-02 |
169973 | IPC: out-of-bounds vector accesses with mismatched vector | - | 2016-10-02 |
169972 | Security: Heap-Buffer-Overflow in usb_api.cc:CreateBufferForTransfer | - | 2016-10-02 |
169966 | IPC: negative integer in command to safe browsing host will cause bad vector access | - | 2016-10-02 |
169770 | IPC: Unvalidated content type used as index for write into raw array | - | 2016-10-02 |
169765 | Security: Integer overflow in libusb_alloc_transfer causes Heap-Buffer-Overflow in chrome.usb.isochronousTransfer | - | 2016-10-02 |
170184 | Heap-buffer-overflow in WebCore::RenderTableSection::nodeAtPoint | - | 2016-10-02 |
170034 | Security: ASAN issue in chromeos::VersionInfoUpdater::OnBootTimes() | - | 2016-10-02 |
169981 | Security: chrome.usb Api missing parameter validation for "length" | - | 2016-10-02 |
169723 | [LangFuzz] Crash at v8::internal::AccessorPair::GetComponent with invalid read | $1,000 | 2016-10-02 |
71115 | Stale pointer in WebCore::RenderTable::firstLineBoxBaseline | $1,000 | 2016-10-02 |
71114 | Stale pointer due to table childs incorrect added | $1,000 | 2016-10-02 |
71167 | Bypass popup blocker using custom event (variation of issue 3275) | - | 2016-10-02 |
70877 | Arbitrary cross-origin bypass using SyntaxError and Number prototype overrides | $1,337 | 2016-10-02 |
70819 | Empty address bar after opening an URL from extension in new tab | - | 2016-10-02 |
70779 | width of boundingClientRect for Range with unicode combining characters is corrupted | - | 2016-10-02 |
70718 | crashes when opening a page with webgl | - | 2016-10-02 |
70589 | race on a linked list in third_party/WebKit/Source/WebCore/platform/sql/chromium/SQLiteFileSystemChromiumPosix.cpp | - | 2016-10-02 |
71027 | REGRESSION: crash after download and close window (only in incognito) | - | 2016-10-02 |
70885 | Bypass popup blocker using iframe | - | 2016-10-02 |
70456 | OOM handler not always properly terminating process | $1,000 | 2016-10-02 |
70538 | Open popup in new tab using java applet | - | 2016-10-02 |
70374 | Browser crash: DeterminePossibleFieldTypesForUpload | - | 2016-10-02 |
70577 | Security: webgl crashes on all tabs + processing spike even after all webgl programs are closed | - | 2016-10-02 |
70376 | Pickle::FindNext reads payload_size without checking that the header is complete | - | 2016-10-02 |
70244 | height of <rect> - integer overflow(?) | $1,000 | 2016-10-02 |
70337 | Regression: new window.onerror() implementation leaks cross-origin Javascript errors | - | 2016-10-02 |
70070 | WebGL crashes depending on uniform names | $500 | 2016-10-02 |
70231 | Prefetch: Do not present authentication prompt | - | 2016-10-02 |
70336 | Cross-origin Javascript error message leak via Worker importScripts() | $500 | 2016-10-02 |
70078 | Crash by form controls with form attributes under orphan nodes | $500 | 2016-10-02 |
69934 | Use after free in LayoutPluginTester.SelfDeletePluginInvoke | - | 2016-10-02 |
69825 | security flaw | - | 2016-10-02 |
69970 | Invalid read in convertV8ObjectToNPVariant | - | 2016-10-02 |
70027 | Stale text node in linebox due to failure to dirty linebox when that text child is dirtied | $1,000 | 2016-10-02 |
69965 | Use after free in geolocation infobars | - | 2016-10-02 |
69628 | Probable memory corruption in WebCore::CounterNode::lastDescendant | $500 | 2016-10-02 |
69597 | Segfault in WebCore::ContainerNode::removeAllChildren() | - | 2016-10-02 |
69569 | Crashed @ IPC::Channel::ChannelImpl::OnIOCompleted when delete browser history | - | 2016-10-02 |
69657 | Not signing out from my https webmail account. | - | 2016-10-02 |
69531 | Valgrind/Memcheck reports uninitialized use of SkGlyph::fMaskFormat in third_party/skia/src/core/SkScalerContext.cpp | - | 2016-10-02 |
69640 | memcheck: read after free in third_party/icu/source/common/unormimp.h | - | 2016-10-02 |
69556 | Issue with merging anonymous block in renderblock::removechild (2) | $1,000 | 2016-10-02 |
69275 | Use after free in scrollbars | - | 2016-10-02 |
69187 | Error prototypes are called on remote scripts | $1,337 | 2016-10-02 |
69159 | Crash @ PasswordStore::RemoveLogin | - | 2016-10-02 |
69106 | ZDI-CAN-1009: Apple Webkit setOuterText Memory Corruption Remote Code Execution Vulnerability | - | 2016-10-02 |
69294 | Browser crash when executing indexedDb tutorial.html in an incognito window. | - | 2016-10-02 |
69195 | playing Z-Type causes crash | - | 2016-10-02 |
68741 | Stale pointers in CSSOM - 2 | $1,000 | 2016-10-02 |
68646 | Integer overflow and signed comparison in RenderView::DidDownloadApplicationIcon() | - | 2016-10-02 |
68641 | Stale form associated element pointer in Document object | $1,000 | 2016-10-02 |
68773 | Chrome: Crash Report - Stack Signature: UTF8ToUTF16(std::basic_string<char,std::char_traits<char>,std::allocator<char> > const &)-382777c6_d21c627c_9e383e89_c1eaa2f5_ef047e8d | - | 2016-10-02 |
68766 | Chrome: Crash Report - Stack Signature: net::HttpStreamFactory::~HttpStreamFactory()-2A77B8F | - | 2016-10-02 |
68434 | Search Bug Dynamic dns | - | 2016-10-02 |
68369 | Installing extensions in "popup"-type windows crash browser | - | 2016-10-02 |
68342 | Aw snap on github.com with voice search extension installed | $500 | 2016-10-02 |
68439 | Destroying nextblock in RenderBlock::removeChild can cause oldChild and nextblock's next sibling to be merged. | $1,000 | 2016-10-02 |
68244 | Playing audio with volume set to undefined crashes browser | - | 2016-10-02 |
68170 | invalid free() in bundled pdf viewer | $1,000 | 2016-10-02 |
68259 | Virus, exploit in maps | - | 2016-10-02 |
68130 | Memory corruption in font draws for accelerated 2d canvas. | - | 2016-10-02 |
68115 | Memory corruption with bad Vorbis streams (from CERT) | $1,000 | 2016-10-02 |
68075 | chrome.dll!WebCore::CounterNode::resetRenderers ExecAV@NULL (7b931db52815b50413964fbdd401fe15) | - | 2016-10-02 |
68062 | OOB read crash in SVG length list parsing algorithm | - | 2016-10-02 |
67968 | Use after free due to adjacent floats not cleared properly from parents | - | 2016-10-02 |
67966 | the bank tell me my browser ar not safe | - | 2016-10-02 |
67923 | Stale pointer in SVGImage | - | 2016-10-02 |
68120 | Stale pointer in CSSFontFaceSource::m_svgFontFaceElement | $1,000 | 2016-10-02 |
177913 | Heap-buffer-overflow in AutofillExternalDelegate::OnSuggestionsReturned | - | 2016-10-02 |
177876 | Heap-use-after-free in webkit::ppapi::PPB_URLLoader_Impl::FillUserBuffer | - | 2016-10-02 |
177858 | Global-buffer-overflow in v8::internal::MaybeObject* v8::internal::SlowQuoteJsonString<unsigned char, v8::internal::SeqOneByte | - | 2016-10-02 |
177932 | Heap-use-after-free in WebCore::SVGElementInstance::invalidateAllInstancesOfElement | - | 2016-10-02 |
177873 | Security: out of bounds write with webgl and gl.DEPTH_COMPONENT | $1,000 | 2016-10-02 |
177688 | ASSERTION FAILED: obj->isRenderInline() || obj == this, Bad cast in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
177620 | Heap-use-after-free in WebCore::HTMLMediaElement::~HTMLMediaElement | $1,000 | 2016-10-02 |
177410 | Heap-use-after-free in extensions::BookmarksIOFunction::ShowSelectFileDialog | - | 2016-10-02 |
177403 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::RenderBlock::clone | - | 2016-10-02 |
177737 | Heap-use-after-free in webrtc::DataChannel::Send | - | 2016-10-02 |
177686 | Heap-use-after-free in WebCore::ImageLoader::dispatchPendingErrorEvent | - | 2016-10-02 |
177815 | pepper_flash_clipboard_message_filter.cc assumed same-sized vectors from untrusted Flash process | - | 2016-10-02 |
176882 | Heap-use-after-free in WebCore::FrameLoader::checkCompleted | $1,000 | 2016-10-02 |
176863 | ASSERTION FAILED: !detachingNode, Heap-buffer-overflow in WebCore::CSSImageGeneratorValue::removeClient | - | 2016-10-02 |
177215 | ASSERTION FAILED: static_cast<unsigned>(m_start + length) <= string.length(), UNKNOWN in WebCore::InlineTextBox::paint | - | 2016-10-02 |
176719 | Global-buffer-overflow in cld::ProcessProbV25UniTote | - | 2016-10-02 |
176692 | postTaskForModeToWorkerContext/dispatchTaskToWorkerThread invalid pointer crash with Workers/FileSystem API | $1,000 | 2016-10-02 |
177197 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::insert<unsigned short> | - | 2016-10-02 |
176738 | ASSERTION FAILED: itemIndex < m_values->size(), UNKNOWN in WebCore::SVGPathSegListPropertyTearOff::processIncomingListItemValue | - | 2016-10-02 |
176514 | Heap-use-after-free in WebCore::RenderObject::propagateStyleToAnonymousChildren | - | 2016-10-02 |
176298 | Heap-buffer-overflow in std::_Rb_tree<int, int, std::_Identity<int>, std::less<int>, std::allocator<int> >::erase | - | 2016-10-02 |
176252 | RenderViewHostImpl::OnMessageReceived | $1,000 | 2016-10-02 |
176137 | Data extraction with XSS Auditor | $500 | 2016-10-02 |
176676 | Heap-use-after-free in cricket::TransportChannelProxy::SetImplementation | - | 2016-10-02 |
176033 | Use-after-free in webrtc::WebRtcSession::data_channel() | - | 2016-10-02 |
176027 | Heap-buffer-overflow in SkARGB32_Opaque_Blitter::blitMask | - | 2016-10-02 |
175741 | UNKNOWN in webkit::ppapi::PluginInstance::PrintPDFOutput | - | 2016-10-02 |
175343 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::AccessibilityMenuListPopup::didUpdateActiveOption | - | 2016-10-02 |
175342 | Heap-use-after-free in WebCore::DeleteButtonController::enable | - | 2016-10-02 |
175305 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
176056 | Global-buffer-overflow in v8::internal::MarkCompactCollector::EmptyMarkingDeque | - | 2016-10-02 |
174920 | Heap-use-after-free in WebCore::CachedCSSStyleSheet::checkNotify | - | 2016-10-02 |
174676 | Heap-use-after-free in SpellcheckHunspellDictionary::InitializeDictionaryLocation | - | 2016-10-02 |
174846 | Heap-use-after-free in WebCore::ElementRuleCollector::collectMatchingRulesForList | - | 2016-10-02 |
175069 | Heap-use-after-free in net::SpdySession::DoLoop | - | 2016-10-02 |
174895 | IndexedDB: missing check that index_ids and index_keys have equal size | - | 2016-10-02 |
174566 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::SVGListProperty<WebCore::SVGPathSegList>::replaceItemValues | - | 2016-10-02 |
174328 | IndexedDB: overflow of 2-bit index id size field | - | 2016-10-02 |
174146 | Crashing in gpu::gles2::GLES2Implementation::ReadPixels(int,int,int,int,unsigned int,unsigned int,void *) | - | 2016-10-02 |
174137 | Crashing in WebCore::ChannelMergerNode::process(unsigned int) | - | 2016-10-02 |
174129 | Security: Silent HTTP Basic Authentification & HTTP Authentification Brute Force | - | 2016-10-02 |
174579 | stack-buffer-overflow in ui::ScrollEvent::Scale on Chrome OS | - | 2016-10-02 |
174150 | Crashing in media::VideoRendererBase::ThreadMain() | - | 2016-10-02 |
174020 | ASSERTION FAILED: !object || object->isMenuList(), UNKNOWN in WebCore::HTMLSelectElement::menuListDefaultEventHandler | - | 2016-10-02 |
173906 | document.referrer leakage with XSS Auditor page block | - | 2016-10-02 |
173880 | Heap-buffer-overflow in media::OpusAudioDecoder::ConfigureDecoder | - | 2016-10-02 |
174049 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderTableSection::layout | - | 2016-10-02 |
174017 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::SVGAnimationElement::currentValuesForValuesAnimation | - | 2016-10-02 |
173781 | Heap-buffer-overflow in void std::__introsort_loop<WebCore::GridTrack**, long, bool | - | 2016-10-02 |
173688 | Security: Non-web-accessible extension URLs should not load in non-extension processes | - | 2016-10-02 |
67393 | Freeing invalid uninitialized pointer to bug_report_ object | $1,000 | 2016-10-02 |
67363 | EXTERNAL-REPORT: SVGElementInstance::m_useElement not cleared on corresponding use element destruction | $500 | 2016-10-02 |
67577 | Switch .jar and .class to always-warn | - | 2016-10-02 |
67234 | Webkit crashes during animation event processing | - | 2016-10-02 |
67303 | renderer crash when playing a corrupt webm video | $1,000 | 2016-10-02 |
67208 | VU#821271 Exception generated by code running in the Stack | $1,000 | 2016-10-02 |
66986 | Reparenting error due to double merge of anonymous blocks in removeChild | - | 2016-10-02 |
66962 | browser crash when reproducing issue #64051 | - | 2016-10-02 |
66931 | Google Chrome crashes at https://webmail.afmc.af.mil/Exchange | - | 2016-10-02 |
66841 | Chrome View keeps changing percentage(decreasing to 50%) automatically | - | 2016-10-02 |
67100 | Crash in PDF form event handling when deleting page from underneath self | - | 2016-10-02 |
66760 | ZDI-CAN-968: Apple Webkit Font Glyph Layout Remote Code Execution Vulnerability | - | 2016-10-02 |
66718 | webgl page causes X server crash | - | 2016-10-02 |
66700 | chrome.dll!WebCore::RenderTextControlSingleLine::speechAttributeChanged ReadAV@NULL (7acb553d23eecf733d9ececf57a499f7) | - | 2016-10-02 |
66676 | REGRESSION: Crash on exit after clearing all downloads | - | 2016-10-02 |
66486 | MAC OSX 10.6.5 google chrome | - | 2016-10-02 |
66473 | Crash in ReplaceSelectionCommand::doApply when modified during mutation event | - | 2016-10-02 |
66748 | CSSCursorImageValue not clearing SVGElement back pointer | $500 | 2016-10-02 |
66334 | Crashes at wild EIP when pressing "print" button on PDFs | - | 2016-10-02 |
65942 | Stale pointer in Range::processContents when modified during mutation event | - | 2016-10-02 |
65869 | crash when rapidly reloading a page with an applet | - | 2016-10-02 |
65845 | Bad cast from RenderText to RenderBox due to details tag being shown inline. | - | 2016-10-02 |
65796 | Children of cloned anonymous blocks should set childreninline flag | - | 2016-10-02 |
65299 | Out of bound read when using modified webp file | $500 | 2016-10-02 |
65194 | Renderer crash @ gpu::gles2::GLES2Implementation::TexSubImage2D(unsigned int,int,int,int,int,int,unsigned int,unsigned int,void const *) | - | 2016-10-02 |
64974 | Integer overflow leading to OOB read, possible memory corruption in webgl getfloat32 | - | 2016-10-02 |
64949 | Crash with progressive rendering | - | 2016-10-02 |
64788 | Access data from my company Google Docs (domain wittit.com) with my gmail account. | - | 2016-10-02 |
64669 | Not allow overwrite of field data when merging profile data | - | 2016-10-02 |
64559 | Bad cast when selection changes for combo boxes. | - | 2016-10-02 |
64456 | Chrome crashes when attempting to install a userscript. | - | 2016-10-02 |
64945 | Crash when webp image is invalid | $1,000 | 2016-10-02 |
64364 | falla al inicio de abrir el navegador | - | 2016-10-02 |
64331 | Stale node being set as layout root when rendering meter, progress elements. | - | 2016-10-02 |
64088 | Use after free due to calling a stale timer on a closed frame/document | - | 2016-10-02 |
64046 | WebKit 49902 - chrome.dll!WebCore::toWebWidgetClient ReadAV@NULL (08ffd4f21a8c6465bb1e19a2f52e4bd5) | - | 2016-10-02 |
63982 | Memory corruption in RenderObjectChildList::removeChildNode | - | 2016-10-02 |
64424 | Computing style on a stale node while sending pending accessibility notification | - | 2016-10-02 |
64108 | Verify cross-origin push fails under SPDY | - | 2016-10-02 |
63911 | Memory corruption in accelerated 2d canvas | - | 2016-10-02 |
63945 | More memory corruption in accelerated 2d canvas, this time in moveTo | - | 2016-10-02 |
63617 | Closing multiple WebGL tabs at the same time causes segfault in Xorg | - | 2016-10-02 |
63609 | Delete any link promotes - Orkut OLD | - | 2016-10-02 |
63552 | Windows media player plugin crashes all the time @ NPAPI::PluginLib::Load+0x116 | - | 2016-10-02 |
63533 | WebM Crash fix merge from M7 | - | 2016-10-02 |
63529 | Security: Segfault when dealing with Web Workers and MessageChannels | - | 2016-10-02 |
63866 | WebKit CSS Font Face Parsing Type Confusion | $1,000 | 2016-10-02 |
63924 | Bad cast from RenderTableCol to RenderBlock in search css | - | 2016-10-02 |
63732 | Browser crash @ JavaScriptAppModalDialog::Cleanup() | $500 | 2016-10-02 |
63389 | Setting small numeric CSS values using setFloatValues changes that value on all pages until the browser is quit | - | 2016-10-02 |
63268 | Universal XSS via mutating style objects and read styles cross origins | - | 2016-10-02 |
63248 | segfault in bundled PDF viewer (invalid read in strlen) | $1,000 | 2016-10-02 |
63444 | Security: possible memory corruption (double-free) in XPath processing code | $1,000 | 2016-10-02 |
63495 | WebCore::NamedNodeMap::setAttributes() stale iterator | - | 2016-10-02 |
63454 | Analyze integer wraps in WebCore::Range. | - | 2016-10-02 |
63380 | SVG Transformlist memory corruption | - | 2016-10-02 |
63031 | Stale font accessed in WebCore::GlyphPage::glyphDataForCharacter | - | 2016-10-02 |
63166 | CryptUnprotectData disclose sensitive information in stack | - | 2016-10-02 |
63051 | chrome_6dc70000!WebCore::EventHandler::updateSelectionForMouseDrag use after free | $500 | 2016-10-02 |
63037 | Security: chrome.google.com Stored XSS | - | 2016-10-02 |
189090 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
189089 | ASSERTION FAILED: curr->isRenderBlock(), UNKNOWN in WebCore::RenderBlock::splitBlocks | - | 2016-10-02 |
189250 | Security: pango loads config options from $HOME/.pangorc | - | 2016-10-02 |
189091 | Heap-use-after-free in extensions::ObjectBackedNativeHandler::Router | - | 2016-10-02 |
189084 | Bad cast in WebKit::WebPageSerializerImpl::endTagToString | - | 2016-10-02 |
187243 | Heap-use-after-free in WebCore::InlineBox::deleteLine | - | 2016-10-02 |
181617 | Security: Possible path traversal in file_util::AbsolutePath (Windows XP/2K3) | $1,337 | 2016-10-02 |
181580 | Heap-use-after-free in extensions::ModuleSystem::LazyFieldGetterInner | - | 2016-10-02 |
187245 | Heap-use-after-free in SkTypeface::getTableSize | - | 2016-10-02 |
188092 | Invalid pointer read in WebCore::WaveShaperProcessor::process | - | 2016-10-02 |
183741 | arbitrary number of popups in response to single user action | - | 2016-10-02 |
181083 | Security: H.264 scaling list parsing overflow | $40,000 | 2016-10-02 |
180920 | Heap-use-after-free in WebCore::ElementRuleCollector::collectMatchingRulesForList | - | 2016-10-02 |
181438 | TransportDIB::Map doesn't validate size of mapped section on Windows | - | 2016-10-02 |
180763 | PWN2OWN: Bad cast in SVGViewSpec::viewTarget | - | 2016-10-02 |
180593 | Heap-use-after-free in WebCore::RenderBlock::logicalRightOffsetForLine | - | 2016-10-02 |
180555 | Security: DevTools renderer navigation is handled in renderer and allows opening any URL in DevTools window. | - | 2016-10-02 |
181375 | Heap-use-after-free in WebCore::AXObjectCache::getOrCreate | - | 2016-10-02 |
180909 | Buffer overflow in URLLoader::ReadResponseBodyAck | - | 2016-10-02 |
180051 | Use after free in PersistentTabRestoreService (during shutdown?) | - | 2016-10-02 |
179653 | ANGLE shader compiler: struct size overflow | - | 2016-10-02 |
179634 | Heap-use-after-free in (anonymous | - | 2016-10-02 |
179632 | Heap-use-after-free in sigslot::_signal_base1<bool, sigslot::single_threaded>::disconnect | - | 2016-10-02 |
179631 | Heap-use-after-free in WebCore::SegmentedString::SegmentedString | - | 2016-10-02 |
179580 | Devtools uses dangling WebContents* when extension reloads | - | 2016-10-02 |
180058 | Security: Loading NaCl from Web via permissive extension | - | 2016-10-02 |
179654 | ANGLE shader compiler: validate numBytes in TPoolAllocator::allocate | - | 2016-10-02 |
178848 | Chrome_Linux: Crash Report - Stack Signature: extensions::UserScriptSlave::GetDataSourceU... | - | 2016-10-02 |
178706 | Mac AVCConfigRecordBuilder: integer overflow leading to heap-buffer-overflow | - | 2016-10-02 |
178780 | Security: Chrome extensions whitelist leaks IDs | - | 2016-10-02 |
178761 | Heap-use-after-free in WebCore::FrameView::maintainScrollPositionAtAnchor | - | 2016-10-02 |
178760 | Heap-use-after-free in gtk_floating_container_add_floating | - | 2016-10-02 |
179287 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::RenderSliderContainer::layout | - | 2016-10-02 |
179522 | Heap-use-after-free in WebCore::AudioNodeOutput::pull | $3,133 | 2016-10-02 |
178797 | Use-after-free under CachedRawResource::responseReceived | - | 2016-10-02 |
178266 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
178242 | NavigationController can copy wrong NavigationEntry when committing a new page | - | 2016-10-02 |
178269 | Heap-use-after-free in WebCore::FrameLoader::stopForUserCancel | - | 2016-10-02 |
178130 | ASSERTION FAILED: node->treeScope() == m_oldScope, Heap-use-after-free in WebCore::TreeScopeAdopter::moveTreeToNewScope | - | 2016-10-02 |
178581 | Heap-use-after-free in BrowsingDataRemover::DoClearCache | - | 2016-10-02 |
178264 | Heap-use-after-free in WebCore::Frame::setPageAndTextZoomFactors | - | 2016-10-02 |
178002 | Heap-use-after-free in WebCore::LiveNodeList::namedItem | - | 2016-10-02 |
177933 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::SVGAnimatedTransformListAnimator::calculateAnimatedValue | - | 2016-10-02 |
178003 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::HTMLElementStack::popCommon | - | 2016-10-02 |
177956 | cross-process memory address leak via sa_restorer | $1,000 | 2016-10-02 |
62987 | Use after free in EventSource | - | 2016-10-02 |
62925 | <Unloaded_S.DLL>+0x42cd17f crash | $1,000 | 2016-10-02 |
62718 | renderer crash in PDF viewer (possibly due to overlapping memcpy) | - | 2016-10-02 |
62674 | Valgrind detected invalid read in net::SingleRequestHostResolver::Cancel() - use-after-free? | - | 2016-10-02 |
62623 | Crash at NULL IP in PDF when evaluating strange expression | $1,000 | 2016-10-02 |
62401 | Crash in WebCore::SMILTimeContainer::begin | $1,000 | 2016-10-02 |
62358 | Integer overflow in SVG Parsing | - | 2016-10-02 |
62791 | Crash loading invalid crx extension file | - | 2016-10-02 |
62354 | Bad cast in SVGImageBufferTools::renderSubtreeToImageBuffer | - | 2016-10-02 |
62296 | Bad cast from renderinline to renderbox in animations | - | 2016-10-02 |
62281 | Use after free due to overhanging floats in LEGEND block | - | 2016-10-02 |
62276 | Out of bound memory access in webp decoder | - | 2016-10-02 |
62261 | use after free in ContainerNode::willRemove | - | 2016-10-02 |
62168 | Bad cast in WebDevToolsFrontendImpl::dispatchOnInspectorFrontend | - | 2016-10-02 |
62158 | Exploitable-looking crash when simply selecting a drop-down value | - | 2016-10-02 |
62293 | Bad cast in CSSStyleSelector::createTransformOperations | - | 2016-10-02 |
62118 | Autosave - Password | - | 2016-10-02 |
61975 | Page is shown before password is requested | - | 2016-10-02 |
61919 | [Regression] Browser crash in GetMostVisitedThumbnailsOnDBThread | - | 2016-10-02 |
61917 | [Regression] Purecall in TopSitesDatabase::UpdatePageThumbnail | - | 2016-10-02 |
62127 | faulty webm file causes segfault | $1,000 | 2016-10-02 |
61954 | split webstorePrivate.install into two functions, one of which requires a gesture | - | 2016-10-02 |
61719 | Chrome | - | 2016-10-02 |
61691 | SECURITY FAIL | - | 2016-10-02 |
61653 | MSVR-10-0108 - Integer Overflow in Chrome's VP8 decoding leads to memory corruption | - | 2016-10-02 |
61634 | webstorePrivate.install method should not suppress install confirmation for extensions with NPAPI | - | 2016-10-02 |
61721 | Security: Google Chrome 7.0.517.41 Multiple DLL Hijacking Vulnerability | - | 2016-10-02 |
61701 | Security: google chrome crashes when a request passes through a proxy and recieves a 407 HTTP error code from the server | - | 2016-10-02 |
61848 | Search results are displayed in bing. | - | 2016-10-02 |
61555 | on double click of a password with comma in it, selects only the part separated by comma instead of selecting fully. The compromises security besides being an inconvenience. | - | 2016-10-02 |
61502 | Floats left out of the incremental line break code due to failed image load. | - | 2016-10-02 |
61338 | pdf viewer segfault after js syntax error | $1,000 | 2016-10-02 |
61577 | Security Bug: Google Docs Published Spreadsheets | - | 2016-10-02 |
61255 | Bad cast in PageClickTracker::handleEvent | - | 2016-10-02 |
61576 | WebKit 48831 - chrome.dll!WebCore::SVGLength::SVGLength WriteAV@Arbitrary (ab566cfad36b72d82883e59d51a1dbec) | - | 2016-10-02 |
61313 | Use after free related to ApplyBlockElementCommand::formatSelection | - | 2016-10-02 |
61129 | Double click selection behaviour exposes password information | - | 2016-10-02 |
60978 | WebGL stencil buffers not correctly initialized | - | 2016-10-02 |
60816 | Crash in hunspell::NodeReader::FindWord | - | 2016-10-02 |
60769 | more bad casts in event handling. | - | 2016-10-02 |
60761 | chrome_1c30000!TabContents::RemoveInfoBar(class InfoBarDelegate * delegate = 0x05dfe700)+0x1dfull tab crash | - | 2016-10-02 |
61158 | Use after free in ApplyStyleCommand::removeInlineStyle | - | 2016-10-02 |
60695 | Bad cast in RenderView docheight,docwidth calc due to adding non box childs | - | 2016-10-02 |
60688 | chrome_55000000!WebCore::FEBlend::apply+0x1a5 | $1,000 | 2016-10-02 |
60653 | Memory error inside WTF::String::format | - | 2016-10-02 |
60496 | Speed tracer + AdBlock = Renderer Crash @ v8::internal::Invoke | - | 2016-10-02 |
60327 | Bad cast to MouseEvent in Node::defaultEventHandler() | $500 | 2016-10-02 |
60238 | Use after free of m_frame in FrameLoader::loadWithDocumentLoader | $500 | 2016-10-02 |
60697 | CSS, background-repeat bug | - | 2016-10-02 |
60029 | OOB read with StringImpl::find line 621 | - | 2016-10-02 |
59817 | Security: Add .html and .htm to the dangerous extensions list for OSX and OS_POSIX | - | 2016-10-02 |
60055 | WebM crash in vp8_setup_intra_recon() | $1,000 | 2016-10-02 |
59663 | CSSPrimitiveValue::cssText() may cause a buffer overflow | - | 2016-10-02 |
60013 | RenderIndicator childs not laid out at all. | - | 2016-10-02 |
223145 | Security: <template> implementation fails to check for "template" in special list when handling "any other end tag for in body" | - | 2016-10-02 |
223125 | Heap-buffer-overflow in WebCore::InlineIterator::atTextParagraphSeparator | - | 2016-10-02 |
223032 | ASSERTION FAILED: !HashTranslator::equal(Extractor::extract(deletedValue), key), Heap-buffer-overflow in WebCore::Font::width | - | 2016-10-02 |
222852 | Heap-use-after-free in WebCore::RenderObject::isDescendantOf | - | 2016-10-02 |
222770 | UNKNOWN in WebCore::QualifiedName* WTF::HashTable<WebCore::QualifiedName, WebCore::QualifiedName, WTF::Identity | - | 2016-10-02 |
222754 | Multiple ffmpeg security issues found by j00ru. | - | 2016-10-02 |
222539 | UNKNOWN in WTF::Vector<WTF::Vector<WebCore::RenderBox*, 1ul>, 0ul>::reserveCapacity | - | 2016-10-02 |
223034 | Heap-buffer-overflow in void media::ToInterleavedInternal<int, long> | - | 2016-10-02 |
223238 | Heap-use-after-free in GIFImageReader::decode | $1,000 | 2016-10-02 |
222000 | Use after free - using speech API after loading a web page | $1,000 | 2016-10-02 |
222036 | Heap-use-after-free in cricket::WebRtcRenderAdapter::FrameSizeChange | - | 2016-10-02 |
222136 | Heap-use-after-free in WebCore::AudioDSPKernelProcessor::reset | - | 2016-10-02 |
221131 | HTML tags are not sanitized in chrome://network | - | 2016-10-02 |
220039 | Security: Chrome extensions can manipulate Chrome sign-in screen | - | 2016-10-02 |
219175 | Security: uid and gid 233 double-allocated to tlsdate-dbus and debugd-logs users/group in Chrome OS ToT | - | 2016-10-02 |
216501 | enable manifest checking in chromiumos-overlay | - | 2016-10-02 |
217858 | [LangFuzz] Crash on Heap with invalid read (possibly due to uninitialized value) on 64 bit | $1,000 | 2016-10-02 |
214314 | Enable GPU process seccomp filter sandbox on Chrome OS | - | 2016-10-02 |
214730 | Security: Remove "--enable-nacl" on daisy/snow boards before production | - | 2016-10-02 |
209604 | Heap-use-after-free in WebCore::RenderObject::container | $1,000 | 2016-10-02 |
213970 | Seccomp filter for avfsd on ARM | - | 2016-10-02 |
203443 | use-after-free in views::View::parent() from chromeos::BalloonContainer::HasBalloonView() | - | 2016-10-02 |
204504 | minijail ignores user/group id and runs as root when it can't find /lib/minijailpreload.so | - | 2016-10-02 |
196575 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderFrameSet::fillFromEdgeInfo | - | 2016-10-02 |
196571 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::Element::offsetParent | - | 2016-10-02 |
196570 | ASSERTION FAILED: !object || object->isCanvas(), UNKNOWN in WebCore::AccessibilityRenderObject::computeAccessibilityIsIgnored | - | 2016-10-02 |
196456 | Any web site can launch Google Talk plug-ins (either of them) by fiddling with ':' in URL syntax | - | 2016-10-02 |
196648 | IPC: destroy routes for video decoders on GpuCommandBufferStub destruction | - | 2016-10-02 |
196174 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
196071 | Security: XMLHttpRequest HTTP Referer Header Faking | - | 2016-10-02 |
194749 | REGRESSION: Chrome crashed while launching Bejeweled game | - | 2016-10-02 |
193197 | Security: Overflow READING BlueZ adapter's config from /var/lib on startup | - | 2016-10-02 |
196393 | RIP == 0 in WebCore::StyleResolver::matchAllRules | $1,000 | 2016-10-02 |
59627 | Renderer crash while profiling @ v8::internal::Context::global_context() | - | 2016-10-02 |
59625 | GPU ANGLE Preprocessor Extension Stack Overflow | - | 2016-10-02 |
59623 | GPU ANGLE Symbol Parsing Multiple Stack Overflows | - | 2016-10-02 |
59593 | Stale pointer in WebCore::ThreadTimers::sharedTimerFiredInternal | - | 2016-10-02 |
59584 | repaired | - | 2016-10-02 |
59554 | Use after free when encountering history.back() call during Page::goToItem execution | $500 | 2016-10-02 |
59504 | WebGL Context GPU Channel Dangling Pointer | - | 2016-10-02 |
59320 | Segfault in x86_64/memset.S below SkScalerContext::getImage on Linux | $1,000 | 2016-10-02 |
59314 | [Merge] Blob / BlobBuilder can be put into bad state with wild integers and strings, due to integer overflows | - | 2016-10-02 |
59036 | PDF JS engine doesn't work in 64 bit | $1,337 | 2016-10-02 |
58829 | Memory corruption in SyncChannel::SyncContext::OnChannelClosed() | - | 2016-10-02 |
59081 | Security: do not allow on-page drag-and-drop from non-same-origin frames (or require an extra gesture) | - | 2016-10-02 |
58731 | Invalid memory access (with possible avenue to corruption) in the xpath handling libxml | $1,000 | 2016-10-02 |
58657 | Bad cast on SVG use element due to mismatched shadow and instance pointers | $1,000 | 2016-10-02 |
58741 | Use after free in HTMLTextFormControlElement::selection() | $500 | 2016-10-02 |
58319 | Browser crash - creating unlimited number of File Dialogs | - | 2016-10-02 |
58008 | Bad cast casting parent class obj InlineFlowBox to child class obj RootInlineBox | - | 2016-10-02 |
57743 | Stale pointer in WebSocket connection handshake | - | 2016-10-02 |
57691 | Security Bug: Uploading without ever choosing to upload | - | 2016-10-02 |
58053 | Crash in BallonViewImpl::DelayedClose() | - | 2016-10-02 |
57908 | build with -fPIE | - | 2016-10-02 |
58069 | Windows Sandbox allows access to the console. | - | 2016-10-02 |
57501 | Crash in PDF plugin when building cross-refs | $500 | 2016-10-02 |
57377 | Cross origin bypass with CSS getMatchedCSSRules() | - | 2016-10-02 |
57347 | ZDI-CAN-874: Apple Webkit WholeText Integer Overflow Remote Code Execution Vulnerability | - | 2016-10-02 |
57200 | Use after free from accessing stale renderers in m_floatingObjects in lowestPosition | - | 2016-10-02 |
57002 | abcd | - | 2016-10-02 |
56996 | Renderer crash when navigating between Field and Aquarium @ WebCore::Node::detach() | - | 2016-10-02 |
56993 | Form data is not cleared or even offered in the "Clear browser history" | - | 2016-10-02 |
57083 | Possible bug with Chrome and PayPal | - | 2016-10-02 |
56760 | segfault in bundled pdf viewer | $1,000 | 2016-10-02 |
57080 | remove extension renaming code | - | 2016-10-02 |
56796 | Bad cast in casting CSSInitialValue to SVGColor in css | - | 2016-10-02 |
56692 | Bad cast from RenderInline to RenderBox in positionListMarker | - | 2016-10-02 |
56621 | use after free in InlineBox::dirtyLineBoxes() | - | 2016-10-02 |
56616 | Bad cast in 3d rendering in RenderObject::getTransformFromContainer | - | 2016-10-02 |
56514 | Click to Play is vulnerable to UI redressing | - | 2016-10-02 |
56653 | Named popup windows bug | - | 2016-10-02 |
56468 | MAJOR Password Security problem | - | 2016-10-02 |
56451 | cross_fuzz: Deleted elements lingering in Document::m_elementsById | - | 2016-10-02 |
56449 | Crash in Pickle::ReadInt in net::HttpResponseInfo::InitFromPickle | - | 2016-10-02 |
56722 | Browser crash on closing incognito @ ToolbarView::Layout() | - | 2016-10-02 |
56474 | User after free in table destroy | - | 2016-10-02 |
56252 | Factory::LookupSymbol+0x3e - Crash | - | 2016-10-02 |
56237 | Browser crash in incognito mode with trying to close a large db. | - | 2016-10-02 |
56206 | Use after free in CounterNode | - | 2016-10-02 |
56144 | Memory corruption in adding text child to table column | - | 2016-10-02 |
56127 | Ă©ÂÂĂŁÂÂĂŁÂÂŸĂŁÂ | - | 2016-10-02 |
56394 | Bad cast in ApplyStyleCommand::applyInlineStyleToPushDown | - | 2016-10-02 |
55957 | Merge webkit bug 45869: Use after free in ImageLayerChromium | - | 2016-10-02 |
55901 | Merge Webkit Bug 45896 :CSS: Fix crash in getTimingFunctionValue() | - | 2016-10-02 |
55751 | vulnerability Google chrome clickjacking | - | 2016-10-02 |
55745 | MSVR-10-0105: Cross origin bypass using canvas and video | - | 2016-10-02 |
55675 | Stale owner element called in frame's disconnectOwnerElement | - | 2016-10-02 |
55607 | Flash intercepts key events when not in focus | - | 2016-10-02 |
55350 | Chrome cross window & cross domain object access | $1,000 | 2016-10-02 |
55831 | Segmentation fault at WebCore::ImageLoader::updateFromElement due to malformed HTML | $1,000 | 2016-10-02 |
55330 | Treebuilder parsing in out of context when encountering special tags like </kbd> | - | 2016-10-02 |
55346 | Load Timer fired on deleted HTMLMediaElement | $1,000 | 2016-10-02 |
230907 | Heap-use-after-free in WebCore::RenderBox::exclusionShapeOutsideInfo | - | 2016-10-02 |
230730 | ASSERTION FAILED: m_insertionPoint->inDocument(), Heap-use-after-free in WebCore::ElementRuleCollector::collectMatchingRulesForList | - | 2016-10-02 |
230729 | Heap-use-after-free in non-virtual thunk to WebKit::WebPluginContainerImpl::clearScriptObjects | - | 2016-10-02 |
230915 | Security: strongSwan ECDSA signature vulnerability | - | 2016-10-02 |
230726 | ASSERTION FAILED: i < m_length, UNKNOWN in WebCore::InlineTextBox::isLineBreak | - | 2016-10-02 |
230725 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
230720 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
230176 | Security: Type confusion vulnerability in V8Clipboard::setDragImageMethodCustom | $1,500 | 2016-10-02 |
230117 | Heap-use-after-free in webkit_media::WebMediaPlayerImpl::paint | $1,000 | 2016-10-02 |
229504 | Interstitials allow bypass of extension permissions | - | 2016-10-02 |
230728 | Heap-use-after-free in WebCore::WidgetHierarchyUpdatesSuspensionScope::moveWidgets | - | 2016-10-02 |
229020 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderLayer::hitTestList | - | 2016-10-02 |
229019 | Input pointer corruption in xmlParseTryOrFinish | - | 2016-10-02 |
227390 | ExtensionFunctionRegistry: missing check for iter != factories_.end() | - | 2016-10-02 |
227350 | Security: UAF in ppapi::ScopedPPResource::CallRelease | $1,000 | 2016-10-02 |
227197 | Security: infoleak in Buffer::Set in O3D | - | 2016-10-02 |
229402 | Another popunder scheme | - | 2016-10-02 |
227158 | Security: domain authorization issue in O3D | - | 2016-10-02 |
227157 | Global-buffer-overflow in WebCore::Font::expansionOpportunityCount | - | 2016-10-02 |
227181 | Security: UAF in O3D | - | 2016-10-02 |
226937 | Security: Postpwnium: Full exploit chain for ChromeOS | $31,336 | 2016-10-02 |
226928 | Null-pointer exec from SkDeferredCanvas::setDeferredDrawing | - | 2016-10-02 |
226696 | Security: use-after-free removing a frame from its parent in a beforeload event of an OBJECT element | $2,000 | 2016-10-02 |
226659 | Harden WTF::Vector::operator[] | - | 2016-10-02 |
226091 | ASSERTION FAILED: !node || node->isShadowRoot(), UNKNOWN in WebCore::EventRetargeter::eventTargetRespectingTargetRules | - | 2016-10-02 |
226090 | Heap-use-after-free in WebCore::IDBDatabase::onComplete | - | 2016-10-02 |
227040 | Heap-use-after-free in moveOverlapping | - | 2016-10-02 |
226068 | Security: HSTS will not work if Strict-Transport-Security header and Public-Key-Pins header are present in this order | - | 2016-10-02 |
226012 | clicking links using generated mouse events bypasses the popup blocker | - | 2016-10-02 |
225979 | Heap-use-after-free in WebCore::RenderTextControl::visiblePositionForIndex | - | 2016-10-02 |
225969 | Consider locking screen when turning screen off rather than when suspending | - | 2016-10-02 |
225798 | Swiftshader images do not use aslr | - | 2016-10-02 |
225565 | Security: strongswan must not write files into /mnt/stateful_partition directly | - | 2016-10-02 |
225546 | Security: u-a-f in shared worker process in Allow{IndexedDB,FileSystem}MainThreadBridge | $1,337 | 2016-10-02 |
225496 | chrome_5eb80000!views::FocusManager::AdvanceFocus Crash | - | 2016-10-02 |
225417 | Heap-use-after-free in TabStripGtk::DestroyDraggedTab | - | 2016-10-02 |
225403 | ASSERTION FAILED: ownerElement->contentFrame() == frame || !ownerElement->contentFrame(), Heap-use-after-free in WebCore::Node::isDescendantOf | - | 2016-10-02 |
225226 | It's possible to bypass the permission restrictions for chrome.tabs.captureVisibleTab | - | 2016-10-02 |
224920 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::RenderBlock::layoutBlockChildren | - | 2016-10-02 |
224734 | Incorporate standalone utilities into futility | - | 2016-10-02 |
223962 | Heap-use-after-free in WebCore::Reverb::latencyFrames | $500 | 2016-10-02 |
224624 | Security: XSS in 1993 chrome | - | 2016-10-02 |
223772 | Attempting free when chrome.fontSettings.getFontList is called twice in background script | - | 2016-10-02 |
223444 | Kernel stack info leak via the tkill and the tgkill syscalls | $500 | 2016-10-02 |
223376 | ASSERTION FAILED: !node || node->isHTMLElement(), UNKNOWN in WebCore::toHTMLElement | - | 2016-10-02 |
223835 | ASSERTION FAILED: candidate.isCandidate(), Heap-use-after-free in WebKit::ChromeClientImpl::didAssociateFormControls | - | 2016-10-02 |
223482 | Heap-use-after-free in WebCore::HTMLTreeBuilder::callTheAdoptionAgency | - | 2016-10-02 |
55257 | Memory corruption in accessing floatptr of a textarea | $1,000 | 2016-10-02 |
55215 | Memory corruption with styled font-face | - | 2016-10-02 |
55179 | Memory corruption with reparentchildren in new treebuilder | - | 2016-10-02 |
55119 | SpdyFramer buffer resizing bug | - | 2016-10-02 |
55114 | Bad cast with svg:g element | $500 | 2016-10-02 |
54794 | HTML5 Workers run outside of the sandbox | - | 2016-10-02 |
54697 | Extension APIs should include password encryption | - | 2016-10-02 |
54691 | segmentation fault in bundled pdf plugin | $1,000 | 2016-10-02 |
54661 | SSL connexion error after update to CHROME v6.0.472.53 | - | 2016-10-02 |
54653 | Memory corruption with creating lines on renderblocks. | - | 2016-10-02 |
54636 | selectedStylesheetSet memory corruption | - | 2016-10-02 |
54539 | OOB read in rendering text fragment | - | 2016-10-02 |
54880 | Crash at gfx::CGImageToSkBitmap | - | 2016-10-02 |
54532 | Issue with incorrect attribute, events handling in SVG and polyline | - | 2016-10-02 |
54500 | Renderer crash on very big animated gif image @ WebCore::RGBA32Buffer::setRGBA(unsigned int *,unsigned int,unsigned int,unsigned int,unsigned int) | $500 | 2016-10-02 |
54312 | My Other MacBook Was Stolen/Robbed from My HOme and the Hacker is taking Pride in Torturing me | - | 2016-10-02 |
54268 | MacOSX WebGL Uninitialized Canvas Information Leak | - | 2016-10-02 |
54262 | Possible Location Bar & SSL Spoofing | $1,000 | 2016-10-02 |
54132 | Security: Insecure library loading in Google Chrome for Linux | - | 2016-10-02 |
54054 | Device3DInitialize Uninitialized Object Vulnerability | - | 2016-10-02 |
54313 | My Other MacBook Was Stolen/Robbed from My HOme and the Hacker is taking Pride in Torturing me | - | 2016-10-02 |
54006 | Security: Extension history permission does not generate a warning | - | 2016-10-02 |
53985 | Crash in chrome_browser_net_websocket_experiment::WebSocketExperimentRunner::DoLoop | - | 2016-10-02 |
53949 | HTTPS -> HTTP redirected CSS and JS do not trigger mixed content | - | 2016-10-02 |
53930 | Memory corruption on Linux when render Khmer script page | - | 2016-10-02 |
53912 | Crash on shutdown in BrowsingInstance::GetSiteInstanceMap | - | 2016-10-02 |
53892 | A Cryptographically secure random number generator implementation for V8 | - | 2016-10-02 |
53836 | wss:// does not validate SSL certs | - | 2016-10-02 |
53747 | Use-after-free of renderer when recalcStyle() is called during layout or painting. | - | 2016-10-02 |
53994 | save | - | 2016-10-02 |
53645 | Function names are exposed to iframes from non-same origin using console API | - | 2016-10-02 |
53640 | Merge Webkit Bug 41523 to 472 | - | 2016-10-02 |
53394 | Geolocation use after free | $500 | 2016-10-02 |
53361 | Browser crash in improper destruction of select file dialog (mac) | $500 | 2016-10-02 |
53230 | crash on google.at ajax search | - | 2016-10-02 |
53176 | BlockedPopupContainer::GetBlockedContents ReadAV@NULL (882a25e76e991e980ffce6adda7cfcc5) | - | 2016-10-02 |
53002 | pop blocker bypass | - | 2016-10-02 |
53142 | EXTERNAL-REPORT: Another Windows kernel CFF font parsing bug | - | 2016-10-02 |
53039 | Geolocation use after free | - | 2016-10-02 |
53017 | MEMORY CORRUPT | - | 2016-10-02 |
53008 | Security: can't update flash from about:plugins in chromium | - | 2016-10-02 |
53068 | download without user permission | - | 2016-10-02 |
53001 | Security: ability to read cross domain image data using toDataURL and getImageData via createPattern | $500 | 2016-10-02 |
52980 | GOOGLE CHOME MEMORY CORRUPT | - | 2016-10-02 |
52961 | Security: user.qzone.qq.com | - | 2016-10-02 |
52958 | Trojan can sync with my sync data ??? | - | 2016-10-02 |
53116 | Security: Chrome can't be downloaded securely. | - | 2016-10-02 |
52870 | error | - | 2016-10-02 |
52782 | close window with javascript | - | 2016-10-02 |
52682 | Sandbox IPC out-of-bounds write in CrossCallParamsEx::CreateFromBuffer | $1,000 | 2016-10-02 |
52587 | cross_fuzz: CSSRule::parentStyleSheet use after free | - | 2016-10-02 |
52581 | HTML5 TreeBuilder ASSERTs on <a><svg><tr><input></a> | - | 2016-10-02 |
52456 | Chrome attempts to connect to HTTP://nikkomsgchannel when focus moves to a password field on any page | - | 2016-10-02 |
52443 | Google Chrome Focus Handling Use-after-free Vulnerability | - | 2016-10-02 |
52420 | MAJOR CHROME SECURITY BUG : Chrome exposes the secrete question and answer for google's gmail password retrial mechanism | - | 2016-10-02 |
51739 | Numerous Integer wraps and errant pointers within WebSockets parser | - | 2016-10-02 |
52413 | Major Chrome security BUG : Confidential User data accessiblity Security Bug :[ Test case of Gmail account registration included] | - | 2016-10-02 |
52204 | Regression: Incorrect destruction of "empty anonymous block" in renderblock remove child. | $1,000 | 2016-10-02 |
52067 | ExtensionsService::IsGalleryDownloadUrl ignores scheme | - | 2016-10-02 |
51919 | use after free in console.profile calls. | $500 | 2016-10-02 |
51865 | Chrome Search Box: Index error | - | 2016-10-02 |
51846 | Null deref when socket stream is closed during hostname resolution | - | 2016-10-02 |
52364 | Valgrind error in CGPDFDrawingContextDraw() on mac ui tests | - | 2016-10-02 |
51727 | autocomplete entries submitted by javascript should not be stored in db (similar to autofill bug 48225) | - | 2016-10-02 |
51709 | Fatal assertion failure when getting gdk custom cursor on safari books | - | 2016-10-02 |
51690 | Security of accounts | - | 2016-10-02 |
51680 | Omnibox url spoofing on pending events in page unload | $500 | 2016-10-02 |
51670 | Security: WebKit: WebCore::GeolocationService::positionChanged use after free | $1,000 | 2016-10-02 |
51658 | Add .xbap to dangerous extensions list | - | 2016-10-02 |
238842 | Crash in WebCore::Canvas2DLayerBridge::prepareForDraw() | - | 2016-10-02 |
238837 | Limit the depth of function calls in GLSL | - | 2016-10-02 |
239013 | Two logins may happen at the same time if network goes offline during login | - | 2016-10-02 |
238041 | document.cookie denial-of-service | - | 2016-10-02 |
237800 | use-after-free on WebCore::MajorGCWrapperVisitor::VisitPersistentHandle | - | 2016-10-02 |
237562 | Security: update curl to resolve CVE-2013-1944 and CVE-2013-2174 | - | 2016-10-02 |
237526 | ~URLRequestFtpJob: NULL deref of request_ | - | 2016-10-02 |
237429 | Heap-use-after-free in WebCore::EventTarget::dispatchEvent | - | 2016-10-02 |
237611 | Security: Screen capture via WebGL texture | $500 | 2016-10-02 |
237104 | Security: CSP doesn't get applied to inline event handlers that were executed once before. | - | 2016-10-02 |
237022 | Cross-origin named subframe access leaks cross-origin subframes of the same name | $1,500 | 2016-10-02 |
236845 | ASSERTION FAILED: node->treeScope() == m_oldScope, Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
237263 | Security: Possible for renderer process to read arbitrary files by tricking session restore | - | 2016-10-02 |
236846 | Global-buffer-overflow in WebRtcIsac_UpdateBwEstimate | - | 2016-10-02 |
236556 | use-after-free on WebCore::FormController::createSavedFormStateMap | - | 2016-10-02 |
236631 | GpuProcessHost: check channel_requests_.empty() | - | 2016-10-02 |
236147 | Heap-use-after-free in printing::PrepareFrameAndViewForPrint::PrepareFrameAndViewForPrint | - | 2016-10-02 |
236269 | ASSERTION FAILED: !m_deletionHasBegun, UNKNOWN in WebCore::DeviceOrientationEvent::~DeviceOrientationEvent | - | 2016-10-02 |
236630 | Security: chronos-writable /var/run/chrome on Chrome OS subject to symlink tricks and other mal manipulations | - | 2016-10-02 |
236245 | Heap-use-after-free in WebCore::FrameView::updateWidget | - | 2016-10-02 |
235638 | ASSERTION FAILED: m_table, Heap-use-after-free in WTF::HashTable<WebCore::SVGElement const*, WTF::KeyValuePair<WebCore::SVGElement const*, WebCore::SV | $1,000 | 2016-10-02 |
235733 | Heap-use-after-free in WebCore::AudioNodeOutput::~AudioNodeOutput | $1,000 | 2016-10-02 |
236139 | ASSERTION FAILED: node->treeScope() == m_oldScope, Heap-use-after-free in void WebCore::Private::addChildNodesToDeletionQueue<WebCore::Node, WebCore::ContainerNode> | $1,000 | 2016-10-02 |
235311 | [LangFuzz] Crash on heap with invalid read on dangerous (possibly uninitialized) address (64 bit) | $500 | 2016-10-02 |
235732 | Heap-buffer-overflow in SkA1_Blitter::blitH | - | 2016-10-02 |
235271 | Security: Isolated Filesystem API does not fully check for references to parent in pathname | - | 2016-10-02 |
234689 | Possible XSS vector in New Tab Page | - | 2016-10-02 |
234809 | URL spoof or renderer kill when committing prerendered/instant page with a pending entry | - | 2016-10-02 |
234937 | Security: the GPU sandbox is not enabled in guest mode on Chrome OS. | - | 2016-10-02 |
235161 | HostResolver can be caused to pass empty DNS components to DnsQuery | - | 2016-10-02 |
234635 | UNKNOWN in cssyyparse | - | 2016-10-02 |
234724 | Chrome Extension API bindings: Definition should not depend on any user/extension mutable prototype objects | - | 2016-10-02 |
234491 | Heap-use-after-free in content::NavigationControllerImpl::RendererDidNavigateToExistingPage | - | 2016-10-02 |
233261 | Heap-use-after-free in content::NotificationServiceImpl::Notify | - | 2016-10-02 |
233848 | ASSERTION FAILED: run.charactersLength() >= run.length(), Heap-buffer-overflow in WebCore::Font::characterRangeCodePath | $500 | 2016-10-02 |
234190 | Heap-use-after-free in SkAlphaRuns::add | - | 2016-10-02 |
234198 | ASSERTION FAILED: value->isValueList(), UNKNOWN in WebCore::createGridPosition | - | 2016-10-02 |
232865 | Potential use after free in ApplyStyleCommand::splitAncestorsWithUnicodeBidi | - | 2016-10-02 |
232743 | use-after-free on WebCore::DOMWrapperMap<void>::removeAndDispose | - | 2016-10-02 |
232633 | use-after-free on net::SSLClientSocketNSS::Core::OnSendComplete | - | 2016-10-02 |
232763 | use-after-free on WebCore::JPEGImageReader::decode | - | 2016-10-02 |
232475 | use-after-free on AutofillPopupControllerImpl::Hide | - | 2016-10-02 |
232393 | Heap-buffer-overflow in WebCore::CSSPrimitiveValue::cleanup | - | 2016-10-02 |
232389 | ASSERTION FAILED: !object || object->isRenderInline(), UNKNOWN in WebCore::RenderTextTrackCue::initializeLayoutParameters | - | 2016-10-02 |
232064 | Heap-use-after-free in WebCore::MediaStreamTrack::stop | - | 2016-10-02 |
232625 | use-after-free on InstantController::ReloadOverlayIfStale | - | 2016-10-02 |
232570 | use-after-free on content::RendererAccessibilityFocusOnly::HandleFocusedNodeChanged | - | 2016-10-02 |
232532 | use-after-free on IPC::ChannelProxy::Context::OnChannelError | - | 2016-10-02 |
232519 | use-after-free on ProfileKeyedServiceFactory::ProfileDestroyed | - | 2016-10-02 |
231688 | Security: Chrome's IntentHandler relies on weak authentication | - | 2016-10-02 |
231128 | UNKNOWN in cricket::VideoFrame::Validate | - | 2016-10-02 |
231127 | Heap-buffer-overflow inWebCore::(anonymous namespace)::fixUnparsedProperties<unsigned char>(unsigned char const*, WebCore::CSSRuleSourceData*) | - | 2016-10-02 |
51525 | Found a bug in the playback of media files via Google Chrome | - | 2016-10-02 |
51511 | Crash in accessibility code on Windows when opening the wrench menu. | - | 2016-10-02 |
51653 | Memory corruption in Counter Nodes. | $500 | 2016-10-02 |
51602 | Investigate rte_fuzz crashes | - | 2016-10-02 |
51630 | Memory corruption in WebSocketChannel::skipBuffer() - underflow in buffer size | $1,337 | 2016-10-02 |
51654 | Memory corruption with moving ruby text nodes to runs without ruby bases. | $1,000 | 2016-10-02 |
51146 | Plain-text information leak of https://user:password due to autosuggest | - | 2016-10-02 |
51070 | Another Windows kernel bug in the CFF font parser | $1,337 | 2016-10-02 |
51240 | Type confusion bug between LargeObjectChunk header and Page header | - | 2016-10-02 |
51464 | Chromium use ActiveX Flash (not the NPAPI one) with potential WinINET cookie leak | - | 2016-10-02 |
51476 | Memory corruption in tree builder | - | 2016-10-02 |
51252 | Use after free with nested use elements | $500 | 2016-10-02 |
50920 | breakdown while alt+z clicked in win7 | - | 2016-10-02 |
50647 | Page with tables crashes the browser | - | 2016-10-02 |
50553 | Crash when closing chrome - BalloonViewImpl::DelayedClose | $1,337 | 2016-10-02 |
50530 | Google Relay Service for the Deaf and Hard of Hearings. | - | 2016-10-02 |
50428 | Browser crash @ TabContents::ExpireInfoBars | - | 2016-10-02 |
50839 | Security: WebKit 43295 - cross_fuzz notification requestPermission memory corruption | - | 2016-10-02 |
50741 | ChromeFrame allows navigation to "gcf:" urls | - | 2016-10-02 |
50712 | Use after free with SVG use referencing svg style element | $1,000 | 2016-10-02 |
50377 | User gesture leaks from prompt (was: infinite prompts) | - | 2016-10-02 |
50253 | Elide long omnibox entries on Mac. | - | 2016-10-02 |
50250 | Use after free in document.close() | $500 | 2016-10-02 |
50110 | Downloading a file adds extension to the extension already in filename | - | 2016-10-02 |
50409 | Zoom bug | - | 2016-10-02 |
50383 | Glibc bug in getaddrinfo() may be exposed | - | 2016-10-02 |
50315 | Code prevents the closing of tab/browser window. | - | 2016-10-02 |
49932 | Failure on page load | - | 2016-10-02 |
49747 | GTK message dialogs do not properly wrap overly long words or elide many short lines in js modal dialog | - | 2016-10-02 |
49745 | Regression: Pop up blocker not working as expected | - | 2016-10-02 |
49729 | Use after free in scroll bar layout | - | 2016-10-02 |
49628 | Memory corruption with invalid text node cast for edit commands | $500 | 2016-10-02 |
49964 | Security: window.history.replaceState fails to enforce domain security | $1,000 | 2016-10-02 |
49910 | Compatibility error with power strip | - | 2016-10-02 |
50029 | Security: showModalDialog() bypasses the usual anti-annoyance checks | - | 2016-10-02 |
49982 | Proxy Config Fail - Security fail | - | 2016-10-02 |
49332 | Autofill can hang the entire browser (DOS) because of stuck on IO Thread processing infinite data | - | 2016-10-02 |
49318 | Merge webkit bug https://bugs.webkit.org/show_bug.cgi?id=39143 | - | 2016-10-02 |
49317 | Merge webkit bug https://bugs.webkit.org/show_bug.cgi?id=40407 | - | 2016-10-02 |
49222 | StringImpl::replace integer overflow | - | 2016-10-02 |
49215 | Signed/Unsigned Comparison issue in MemoryAllocator::AllocateRawMemory | - | 2016-10-02 |
49596 | Security issue in SVGUseElement::buildShadowTree | $500 | 2016-10-02 |
49377 | X509Certificate::Cache usage pattern may result in use after free | - | 2016-10-02 |
49346 | Sync allows an attacker who compromises Google credentials to push extensions to a user's browser | - | 2016-10-02 |
49166 | kdsfgmkladsfjljdf | - | 2016-10-02 |
49188 | ChromeFrame window.open("javascript:window.open('http://example.com/');"); => NULL ptr crash | - | 2016-10-02 |
48857 | Render crash in FormManager::FindCachedFormElement() | - | 2016-10-02 |
49177 | Extension updates don't identify privilege increases when scheme changes | - | 2016-10-02 |
49172 | AutoFill causes browser crash when saving large profiles | - | 2016-10-02 |
49047 | Open a share-point site will cause the browser to crash | - | 2016-10-02 |
48499 | Should autofill credit card infomation over an https page only | - | 2016-10-02 |
48330 | Security: WebSocket: Integer underflow in header length calculation triggers browser DoS | - | 2016-10-02 |
48288 | Crash site | - | 2016-10-02 |
48597 | Incorrect eliding (windows), truncation(linux) for hostname in security information dialog | - | 2016-10-02 |
48733 | Crash in third_party xdg_mime library when unable to handle long file paths | $1,337 | 2016-10-02 |
48440 | Localhost XSS | - | 2016-10-02 |
48282 | LegacyHTMLTreeBuilder fires DOM mutation events | - | 2016-10-02 |
48233 | Steal any autofill field using javascript while user is hovering over one of the selection. | - | 2016-10-02 |
247038 | Heap-use-after-free in WebCore::V8HTMLFormControlsCollection::indexedPropertyGetter | - | 2016-10-02 |
246724 | Security: Ensure that all request types use pinning | - | 2016-10-02 |
48284 | <use> on <font-face> causes crashes, if SVGUseElement gets detached | $500 | 2016-10-02 |
246635 | Heap-buffer-overflow in WebCore::HTMLMapElement::imageElement | - | 2016-10-02 |
246240 | ResourceHostMsg_DataReceived_ACK: heap corruption | - | 2016-10-02 |
246205 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
246203 | Heap-use-after-free in WebCore::V8GCController::opaqueRootForGC | - | 2016-10-02 |
48283 | EXTERNAL-REPORT: Windows kernel crash on invalid font | $1,337 | 2016-10-02 |
246701 | UNKNOWN in WebCore::DownSampler::process | - | 2016-10-02 |
245727 | Heap-use-after-free in WebCore::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
245153 | PDF: OOB read in JPEG2000 image handling | - | 2016-10-02 |
245941 | Heap-use-after-free in base::internal::CallbackBase::Reset | - | 2016-10-02 |
245368 | Infobar Google Update plugin by default | - | 2016-10-02 |
244415 | SpeechRecognizerImpl UaF | - | 2016-10-02 |
244260 | Security: TLS Truncation attack on HTTP headers, including cookie flags | $3,133 | 2016-10-02 |
244056 | Heap-use-after-free in WebCore::RenderTextFragment::willBeDestroyed | - | 2016-10-02 |
244036 | ASSERTION FAILED: node->parentNode(), Heap-use-after-free in WebCore::RenderBox::exclusionShapeOutsideInfo | $1,000 | 2016-10-02 |
244021 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImages | - | 2016-10-02 |
243991 | Heap-use-after-free in WebCore::InputType::stepUpFromRenderer | $1,000 | 2016-10-02 |
243881 | ASSERTION FAILED: actualInfo->derefObjectFunction == V8HTMLSpanElement::info.derefObjectFunction, UNKNOWN in WebCore::wrap | - | 2016-10-02 |
245121 | Security: Cloud-printing Robot-Account storage in Local State lacks integrity, permits redirection to evil printers | - | 2016-10-02 |
244746 | UrlRequestContext can be deleted while a live SocketStream has a pointer to it (vtable UAF) | $3,133 | 2016-10-02 |
244080 | UNKNOWN in v8::internal::Object::GetProperty | - | 2016-10-02 |
243339 | Security: CheckDuplicateHandle (BreakDebugger) browser crash with (Web) Workers and WebSQL | $2,000 | 2016-10-02 |
242931 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
242924 | [LangFuzz] Crash at v8::internal::HeapObject::Size() on 64 bit with invalid read | $1,000 | 2016-10-02 |
242819 | Security: Registering on Gerrit with Any Email [Auth Problem] | - | 2016-10-02 |
242786 | Heap-double-free in av_destruct_packet | - | 2016-10-02 |
243512 | base/time_posix executes signed overflow with 64-bit time_t | - | 2016-10-02 |
243875 | ResourceHostMsg_RequestResource: validate request_data.priority enum | - | 2016-10-02 |
243818 | Heap-use-after-free in WebCore::StyledElement::ensureMutableInlineStyle | $1,000 | 2016-10-02 |
243045 | ASSERTION FAILED: !m_deletionHasBegun, Heap-use-after-free in WebCore::GenericEventQueue::enqueueEvent | - | 2016-10-02 |
242322 | Escalate access to browser internals | $500 | 2016-10-02 |
242224 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::~BaseMultipleFieldsDateAndTimeInputType | $1,000 | 2016-10-02 |
242114 | Heap-use-after-free in WebCore::Range::compareBoundaryPoints | - | 2016-10-02 |
242762 | Security: Use-after-free in net::SocketStream::Finish | $3,133 | 2016-10-02 |
242702 | NSS is unable to open /dev/urandom on OS X, resulting in insufficient entropy for renderers | - | 2016-10-02 |
242502 | UNKNOWN in v8::internal::TypeFeedbackOracle::CanRetainOtherContext | - | 2016-10-02 |
240984 | Security: Merge http://trac.webkit.org/changeset/150072 | - | 2016-10-02 |
240961 | Zero-sized textures must be considered incomplete | - | 2016-10-02 |
240706 | Security: perf_swevent_init does not check negative argument | - | 2016-10-02 |
242023 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
241607 | `git cl upload` can add patches to other peoples' issues | - | 2016-10-02 |
241139 | Heap-use-after-free in webkit_glue::WebURLLoaderImpl::Context::OnReceivedResponse | $1,000 | 2016-10-02 |
240124 | Heap-use-after-free in WebCore::ImageInputType::attach | $1,000 | 2016-10-02 |
240056 | UNKNOWN in int v8::internal::FlexibleBodyVisitor<v8::internal::NewSpaceScavenger, v8::internal::JSObject::BodyD | - | 2016-10-02 |
240139 | Security: gerrit.chromium.org is running an outdated version of OpenId4Java | - | 2016-10-02 |
240057 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
240449 | Crash in base::DeleteHelper<safe_browsing::DownloadProtectionService::CheckClientDownloadRequest>::DoDelete(void const *) | - | 2016-10-02 |
240490 | Security: Set HSTS preloads for translate.google[apis].com | - | 2016-10-02 |
240055 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
239699 | Instant Extended on mobile platforms allows sboxchip spoofing | - | 2016-10-02 |
239580 | Heap-use-after-free in net::SniffMimeType | - | 2016-10-02 |
240054 | ASSERTION FAILED: m_requestCount == 0, Heap-use-after-free in WebCore::CachedResourceLoader::decrementRequestCount | - | 2016-10-02 |
240032 | Security: chrome_70ee0000!v8::internal::ScavengingVisitor<1,1>::EvacuateShortcutCandidate crash | $500 | 2016-10-02 |
239897 | Tab crashes when changing <audio> element source when used with Web Audio API | $500 | 2016-10-02 |
239411 | ANGLE: check negative vector/matrix/array index | - | 2016-10-02 |
239134 | PDF: bad free in JBIG2 PDF decoder | - | 2016-10-02 |
48115 | REGRESSION: Memory corruption in open source JPEG decoder (r61619) | $500 | 2016-10-02 |
48167 | Security: CRITICAL EXECUTABLE MISSING FUNCTION FLAW | - | 2016-10-02 |
48043 | dadasdadasdas | - | 2016-10-02 |
48225 | Autofill profile (address, perfsonal info) spam without any need of user interaction | - | 2016-10-02 |
48093 | Chromoting enabled by default in Chromium | - | 2016-10-02 |
47105 | Renderer crash for a multipart page | - | 2016-10-02 |
47866 | Memory corruption with crash in RenderObject::containingBlock() | $500 | 2016-10-02 |
47253 | ref_fuzz crash 2 | - | 2016-10-02 |
47252 | ref_fuzz crash | - | 2016-10-02 |
47160 | possblie access file: chrome: | - | 2016-10-02 |
47395 | Security: Modification over GUI | - | 2016-10-02 |
47086 | Memory corruption with DOM mutation on onchange event firing for select object | - | 2016-10-02 |
47056 | Browser crash after AppModalDialogQueue::ShowNextDialog | - | 2016-10-02 |
47915 | ZDI-CAN-806: Apple Safari's Webkit Runin Use-after-free Vulnerability | - | 2016-10-02 |
47938 | error tags html | - | 2016-10-02 |
47515 | Security: Reproducable and Controllable Memory Leak in about:memory page | - | 2016-10-02 |
46750 | Browser crash in WebSocket creation | - | 2016-10-02 |
46575 | DoS by opening unlimited number of print dialogs | - | 2016-10-02 |
46516 | Need to sync extension permissions | - | 2016-10-02 |
46509 | error al descargar | - | 2016-10-02 |
46452 | ::-webkit-scrollbar causes "Aw Snap" when combined with certain JavaScripts | - | 2016-10-02 |
46401 | Google Chrome does not prompt for user permission before using HTML5's offline features | - | 2016-10-02 |
46360 | Memory corruption in :first-letter rendering | $500 | 2016-10-02 |
46792 | Security Vulnerability in Chrome 5.0.375.70 | - | 2016-10-02 |
46788 | help me! | - | 2016-10-02 |
46008 | Wrapping shared memory allocation in X backing store | - | 2016-10-02 |
46018 | Crash - BalloonViewImpl::DelayedClose | - | 2016-10-02 |
45923 | Browser not checking site's domain on password type inputs | - | 2016-10-02 |
45876 | Web pages should NOT be able to load resources if there are NO content scripts from that extension on the page | - | 2016-10-02 |
45799 | possible privilege escalation via named pipes (NaCL) | - | 2016-10-02 |
45683 | jjjjj | - | 2016-10-02 |
46126 | crash with processing invalid x509-user-cert responses. | $500 | 2016-10-02 |
45983 | Segmentation fault in WebCore::RenderLayer::paintList when a malformed PNG image is viewed | $1,000 | 2016-10-02 |
45614 | ZDI-CAN-782: Apple Webkit SVG First-Letter Style Remote Code Execution Vulnerability | - | 2016-10-02 |
45615 | ZDI-CAN-785: Apple Webkit SVG Floating Text Element Remote Code Execution Vulnerability | - | 2016-10-02 |
45524 | crash | - | 2016-10-02 |
45506 | User ID Issue | - | 2016-10-02 |
45494 | Function names are exposed to iframes from non-same origin using console API | - | 2016-10-02 |
45412 | Trojan Horse exploit_c.FWR | - | 2016-10-02 |
45267 | ViewHostMsg_UpdateVideo memory corruption | - | 2016-10-02 |
45164 | Crash with invalid images. | - | 2016-10-02 |
45659 | Stale pointer in SVGResourceFilter | - | 2016-10-02 |
45609 | ZDI-CAN-784: Apple Webkit Rendering Counter Remote Code Execution Vulnerability | - | 2016-10-02 |
44955 | Need to merge WebCore::toAlphabetic() crash to 375 branch. | - | 2016-10-02 |
44868 | Geolocation events fire after document deletion | - | 2016-10-02 |
44835 | 1337 on goggle search | - | 2016-10-02 |
44796 | Please disallow "javascript:" URLs in the address bar | - | 2016-10-02 |
45033 | Issue with frames[].location | - | 2016-10-02 |
44742 | a bug of the scrollbar in iframe | - | 2016-10-02 |
44740 | Need to merge fix for WebKit font issue to 375 branch | - | 2016-10-02 |
44658 | Security: Insecure behavior in /tmp by Keystone on Mac OS X | $500 | 2016-10-02 |
44759 | sad tab with little script | - | 2016-10-02 |
44556 | Security: WebKit: WebCore::RenderInline::destroy ExecAV@Arbitrary (b1c9c3c46df454874e36c9f86b2418fa) | - | 2016-10-02 |
44424 | security:chrome_1c30000!WebCore::InlineBox::paint+0x70 | $500 | 2016-10-02 |
44193 | Security: Chrome saves plaintext passwords even when "save passwords" is disabled | - | 2016-10-02 |
43967 | REGRESSION: Currently loading subresource displayed in omnibox | - | 2016-10-02 |
43902 | innerHTML decompilation issues in textarea | - | 2016-10-02 |
43846 | Null deref during image drag, crash in drag selection controller. | - | 2016-10-02 |
43813 | chrome_1c30000!SkAlphaRuns::Break+0x13 - Memory Corruption | $500 | 2016-10-02 |
44500 | Invalid read handling malformed SVG <use> element | - | 2016-10-02 |
43487 | ZDI-CAN-765: CSS Charset Text Transformation Vulnerability | - | 2016-10-02 |
43446 | Kapersky Vulnerablity | - | 2016-10-02 |
43315 | [MD audit] Stale pointer error when normalizing DOM nodes | - | 2016-10-02 |
43307 | [MD audit] Possible memory corruption with bad bitmap shared memory object in clipboard IPC | - | 2016-10-02 |
43304 | [MD audit] Linux sandbox escape | - | 2016-10-02 |
42989 | Mac sandbox allows calls to stat() on arbitrary paths. | - | 2016-10-02 |
43488 | ZDI-CAN-766: SVG ForeignObject Rendering Layout Vulnerability | - | 2016-10-02 |
43322 | [MD audit] Problems with video messages and sizes | - | 2016-10-02 |
257892 | Security: local user can crash a system service daemon, causing DOS | - | 2016-10-02 |
257852 | FileUtilitiesMessageFilter::OnOpenFile insufficient permission checks | - | 2016-10-02 |
257357 | Heap-use-after-free in WebCore::CSSFontFace::setLoadState | - | 2016-10-02 |
257353 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::destroyShadowSubtree | - | 2016-10-02 |
257748 | Security: Origin bypass by writing window.frames[i] | $500 | 2016-10-02 |
257875 | UNKNOWN in _getKeywords | - | 2016-10-02 |
257363 | Security: ANGLE libGLESv2 Integer Overflow | $1,337 | 2016-10-02 |
256724 | Remove the RELOAD exception for validating 1993 search chains | - | 2016-10-02 |
257347 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
257348 | ASSERTION FAILED: !m_hasAXObject, Heap-use-after-free in WebCore::AccessibilityRenderObject::remoteSVGRootElement | - | 2016-10-02 |
256531 | Issues with HSTS / HPKP state tracking | - | 2016-10-02 |
257262 | Security: UAF in content::WebContentsObserver::web_contents() | - | 2016-10-02 |
256288 | Security:Quota Management API's bug | - | 2016-10-02 |
255934 | ASSERTION FAILED: width == frameRect.width(), UNKNOWN in WebCore::WEBPImageDecoder::applyPostProcessing | - | 2016-10-02 |
256013 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImages | - | 2016-10-02 |
255931 | Heap-use-after-free in qcms_profile_from_memory | - | 2016-10-02 |
255524 | Heap-use-after-free in content::RenderProcessHostImpl::ProcessDied | - | 2016-10-02 |
256020 | Pasting a URL into the infobar, then hitting enter does not cause a scroll to the left | - | 2016-10-02 |
256057 | going into fullscreen can be performed without even being in the foreground | - | 2016-10-02 |
256280 | Security: Linux kernel perf interface allows tracing of setuid processes | - | 2016-10-02 |
255932 | Heap-use-after-free in WTF::KeyValuePair<WTF::StringImpl*, WTF::RefPtr<WebCore::KeyframeAnimation> >* WTF::HashTable<WTF::S | - | 2016-10-02 |
255523 | Security: X client library bugs allow malicious X servers to attack clients | - | 2016-10-02 |
254728 | Heap-use-after-free in WebCore::AudioBufferSourceNode::renderFromBuffer | - | 2016-10-02 |
254460 | Heap-buffer-overflow in url_parse::ExtractFileName | - | 2016-10-02 |
254159 | Security: Chrome shared memory file can be world readable and lacks security checks when opening existing mappings. | $500 | 2016-10-02 |
253550 | ASSERTION FAILED: isMainThread(), Heap-use-after-free in WebCore::WaveShaperDSPKernel::lazyInitializeOversampling | $500 | 2016-10-02 |
253481 | Security: Insecure page shown as secure (insecure inlines and named anchors) | - | 2016-10-02 |
255165 | Heap-use-after-free in content::WebPluginProxy::Paint | - | 2016-10-02 |
254928 | Heap-use-after-free in net::HostResolverImpl::Job::OnDnsTaskFailure | - | 2016-10-02 |
254783 | Heap-use-after-free in WebCore::RenderObject::destroyAndCleanupAnonymousWrappers | $1,000 | 2016-10-02 |
252712 | Security: Use-after-free in RadioInputType::handleKeydownEvent | - | 2016-10-02 |
252216 | Security: spawn multiple windows in response to a single user interaction | - | 2016-10-02 |
252062 | Security: an attacker can sign-in a victim to his own account. | - | 2016-10-02 |
252034 | Security: NPAPI extension can be synced | - | 2016-10-02 |
252848 | SpeechRecognitionManagerImpl::SessionStart: vector::front() on an empty vector. | - | 2016-10-02 |
252888 | Security: <input type="file" directory> can trick user into uploading their entire Download/Desktop folder. | $1,000 | 2016-10-02 |
250003 | Use-after-free by navigating out a document during form validation message is shown | - | 2016-10-02 |
249854 | MediaStreamHostMsg_GenerateStream: validate audio_type / video_type enums | - | 2016-10-02 |
249640 | Heap-use-after-free in WebCore::Node::setNeedsStyleRecalc | - | 2016-10-02 |
252010 | Chromium sync session fixation + code execution | $21,500 | 2016-10-02 |
249335 | Flash settings menu vulnerable to clickjacking | - | 2016-10-02 |
251711 | Security: SVG Filter Timing Attack | - | 2016-10-02 |
249502 | Security: (Shared) (WebSQL) Worker races cause invalid pointers in DatabaseObserver::databaseClosed and DatabaseObserver::reportOpenDatabaseResult | $1,000 | 2016-10-02 |
249199 | Heap-use-after-free in WebCore::ApplyStyleCommand::removeInlineStyle | - | 2016-10-02 |
248960 | Heap-use-after-free in gfx::RenderTextWin::GetGlyphBounds | - | 2016-10-02 |
248950 | Heap-use-after-free in WebCore::Document::dispose | - | 2016-10-02 |
248843 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImages | - | 2016-10-02 |
248840 | Heap-use-after-free in WebCore::RenderBlock::willBeDestroyed | - | 2016-10-02 |
249246 | Security: Open in incognito window doesn't work in panel. | - | 2016-10-02 |
249064 | IndexedDBHostMsg_DatabaseGet: validate params.object_store_id | - | 2016-10-02 |
247964 | Stack-buffer-overflow in cricket::ToString | - | 2016-10-02 |
248023 | ASSERTION FAILED: m_path, UNKNOWN in SkPath::isEmpty | - | 2016-10-02 |
42980 | Sandboxed iframes should not autocomplete/autofill unless allow-same-origin set | - | 2016-10-02 |
42765 | top.close() is allowed on iframe@sandbox when allow-same-origin is not set | - | 2016-10-02 |
42723 | Table layout crash bug from wushi | $500 | 2016-10-02 |
42578 | Navigation bar problem | - | 2016-10-02 |
42575 | sessionStorage is shared on iframe@sandbox | - | 2016-10-02 |
42574 | Sandboxed iframes should not allow navigation to history forward,back without allow-top-navigation set. | - | 2016-10-02 |
42538 | segfault in net::X509Certificate::Verify [Linux] | - | 2016-10-02 |
42396 | Security: WebKit: WebCore::WebGLUnsignedIntArrayInternal::getCallback ReadAV@Arbitrary (deef89ee3d0345edebeaf13cf974c47c) | - | 2016-10-02 |
42391 | Chromium exposes file paths when dropping files | - | 2016-10-02 |
42356 | User scripts can access chrome:// URLs | - | 2016-10-02 |
42755 | Merge fix for WebKit CSS hover security bug to 375 | - | 2016-10-02 |
42736 | Memory corruption (read random system memory) or crash | $500 | 2016-10-02 |
42300 | Memory corruption / corrupt function pointer usage with bad AAC SBR | - | 2016-10-02 |
42294 | WebCore::FontFallbackList::determinePitch memory corruption (0b4c05aab686a31bc4954a5bd6bae27b) | $500 | 2016-10-02 |
41878 | Problemas para abrir paginas webs | - | 2016-10-02 |
41778 | "Go To" right click context menu option can open arbitary urls like chrome:// file:// etc. | - | 2016-10-02 |
41654 | Security: Permanent Clipboard Hijack | - | 2016-10-02 |
41469 | Drag and drop bad reference counting leads to re-use of freed memory: WebCore..String..length ReadAV@Arbitrary (394bb1a56acd66a43221b2a08fa5b25a) | - | 2016-10-02 |
42306 | Possible num_patches array indexing errors in AAC SBR | - | 2016-10-02 |
42228 | Security: a malicious page may gain access to context of an extension's content script | - | 2016-10-02 |
41334 | Security: Selecting a address label in an address form field ALSO fills the default credit card | - | 2016-10-02 |
41330 | Security: Label Name truncation with long field values leading to autofill data theft | - | 2016-10-02 |
41265 | Security: Clicking an address form field shows credit card labels and can fill credit card fields. | - | 2016-10-02 |
40801 | OOB Array Indexing Bug | - | 2016-10-02 |
41428 | MALWARE | - | 2016-10-02 |
41427 | Security: Autofill does not store sensitive data like cc info as encrypted on disk, should mimic password manager | - | 2016-10-02 |
40628 | WebKit: WebCore::PageGroupLoadDeferrer::PageGroupLoadDeferrer ReadAV@NULL (7a3291a05aead0cc3a4bc8a6b440d145) | - | 2016-10-02 |
40605 | Redirecting to a data URI without a / in the data section crashes the entire browser | - | 2016-10-02 |
40575 | An HTTP page loaded quickly after NTP can gain DOMUI bindings privilege | - | 2016-10-02 |
40487 | <video> inside <foreignObject> inside <svg> inside <img> --> crash | - | 2016-10-02 |
40445 | Cross Origin Bypass using iframe & " " on JAVASCRIPT URI | $1,000 | 2016-10-02 |
40219 | Security: logged into google account but got gmail account | - | 2016-10-02 |
40173 | Termination bugs in GpuProcessHost | - | 2016-10-02 |
40147 | Security: XSS issue in the FTP parser | - | 2016-10-02 |
40635 | Security: v8: WebKitPoint() memory corruption | $500 | 2016-10-02 |
40137 | Security: XSS in net-internals | - | 2016-10-02 |
39985 | Cross-origin bypass: Javascript URL can be set in iframe.src via numerous DOM aliases (via Node and NamedNodeMap) | $1,000 | 2016-10-02 |
40138 | Security: XSS in chrome://downloads | - | 2016-10-02 |
39861 | Cross-origin image theft via SVGs as a canvas pattern | - | 2016-10-02 |
40136 | Security: Path Traversal in Devtools | - | 2016-10-02 |
39698 | Security: Synchronous preflight XHR allows arbitrary XSRF | - | 2016-10-02 |
39660 | Need to merge fix for CSSPrimitiveValue::setFloatValue() type confusion error | - | 2016-10-02 |
39443 | crash with form tag | $500 | 2016-10-02 |
39303 | icudt42.dll does not support ASLR(on Win7/Vista) | - | 2016-10-02 |
39277 | Browser GDI crash with excessive downloads. | - | 2016-10-02 |
38937 | show bug | - | 2016-10-02 |
38920 | extensions can circumvent access restrictions by over-writing chromeHidden.event.dispatchJSON | - | 2016-10-02 |
38890 | "AutoFill Profiles"-feature information disclosure issue | - | 2016-10-02 |
39740 | Plugins are not always blocked by content settings | - | 2016-10-02 |
39639 | url redirect | - | 2016-10-02 |
38650 | Chrome downladed XP Defender Pro java based virus from a website | - | 2016-10-02 |
38512 | libpng < (1.4.1|1.2.43) suffer DoS issues (CVE-2010-0205) | - | 2016-10-02 |
38310 | Security: *.kaiserpermanente.org sites report SSL Error (certificate failures), only on Linux | - | 2016-10-02 |
38749 | HTTPS | - | 2016-10-02 |
38845 | Out of bounds array read in FTP network transaction | - | 2016-10-02 |
38550 | Mac: Don't send client cert before verifying received server cert | - | 2016-10-02 |
38238 | Reproducible renderer crash on javascript | - | 2016-10-02 |
266922 | Security: Address bar spoofing possible after navigating to an unhandled protocol | - | 2016-10-02 |
266364 | Heap-use-after-free in WebCore::DocumentLoader::handleSubstituteDataLoadNow | - | 2016-10-02 |
266346 | Widevine CDM is running with excessive permissions | - | 2016-10-02 |
265930 | V8 SMI-only array optimizations misbehave with arrays created using the Array constructor of a different document | - | 2016-10-02 |
265894 | UNKNOWN in v8::internal::JSObject::SetPropertyForResult | - | 2016-10-02 |
265838 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | $2,000 | 2016-10-02 |
266729 | strongswan denial-of-service vulnerability (CVE-2013-5018) | - | 2016-10-02 |
266593 | ASSERTION FAILED: !element || element->hasTagName(summaryTag), UNKNOWN in WebCore::DetailsMarkerControl::summaryElement | - | 2016-10-02 |
265221 | Security: URL spoof with http status 204 | $500 | 2016-10-02 |
264988 | Chrome webrtc crashes if i try to remove remote video track in peer connection. | - | 2016-10-02 |
264607 | SyzyASAN: Heap-use-after-free in GrTextureAccess::reset | - | 2016-10-02 |
264574 | ASSERTION FAILED: !renderer->needsLayout(), Heap-use-after-free in WebCore::RenderBlock::LineBreaker::nextSegmentBreak | - | 2016-10-02 |
265731 | Security: mach_override_ptr maps rwx pages at fixed address and leaves PROT_WRITE on text pages | - | 2016-10-02 |
265493 | use-after-free on content::GpuVideoDecodeAcceleratorHost::OnErrorNotification | - | 2016-10-02 |
264211 | ASSERTION FAILED: run.charactersLength() >= run.length(), Heap-buffer-overflow in WebCore::Font::characterRangeCodePath | - | 2016-10-02 |
263811 | UNKNOWN in v8::internal::Heap::AllocateJSObject | - | 2016-10-02 |
263878 | Security: kernel CVE-2013-4125 fib6_add_rt2node | - | 2016-10-02 |
264212 | Heap-use-after-free in WebCore::Node::setCustomElementState | - | 2016-10-02 |
263810 | ASSERTION FAILED: !object || object->isRenderBlock(), UNKNOWN in WebCore::RenderBox::containingBlockLogicalHeightForPositioned | - | 2016-10-02 |
264504 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | $2,000 | 2016-10-02 |
263923 | Heap-use-after-free in WebCore::Scrollbar::invalidateRect | - | 2016-10-02 |
263214 | Security: SSLPolicy isn't checking the error associated with a saved exception | - | 2016-10-02 |
263178 | Heap-use-after-free in content::IndexedDBDatabase::DeleteDatabase | - | 2016-10-02 |
262653 | Heap-use-after-free in WebCore::RootInlineBox::closestLeafChildForPoint | $1,000 | 2016-10-02 |
263386 | ASSERTION FAILED: !node || node->isShadowRoot(), UNKNOWN in WebCore::EventRetargeter::eventTargetRespectingTargetRules | - | 2016-10-02 |
263255 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
262531 | Heap-buffer-overflow in FindSortableTop | - | 2016-10-02 |
262177 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
261898 | Heap-buffer-overflow in autofill::AutofillPopupControllerImpl::UpdateDataListValues | $1,000 | 2016-10-02 |
262606 | use-after-free - speech API and window.close() ::SpeechRecognitionBubbleView::GetAnchorRect+0x23 | $1,000 | 2016-10-02 |
261891 | Heap-use-after-free in WebCore::RenderFlexibleBox::firstLineBoxBaseline | - | 2016-10-02 |
261836 | Heap-use-after-free in WebCore::Document::detach | $3,000 | 2016-10-02 |
261609 | Heap-use-after-free in WebCore::IdTargetObserverRegistry::removeObserver | - | 2016-10-02 |
261454 | Heap-use-after-free in sk_atomic_inc | - | 2016-10-02 |
261711 | Security: Upgrade to openssl 1.0.1e (or later) | - | 2016-10-02 |
260667 | Security: Content process crash on (new Window.prototype.__proto__.constructor).toString(); | - | 2016-10-02 |
260428 | Heap-use-after-free in WebCore::TimerBase::start | $1,000 | 2016-10-02 |
260165 | Heap-use-after-free in WebCore::MutationObserverRegistration::~MutationObserverRegistration | $1,000 | 2016-10-02 |
260156 | Heap-use-after-free in content::WebMediaPlayerImpl::paint | $1,000 | 2016-10-02 |
260138 | Heap-use-after-free in WebCore::ElementShadow::removeAllShadowRoots | - | 2016-10-02 |
260110 | Heap-use-after-free in WebCore::copyKeysToReferencingVector | $1,000 | 2016-10-02 |
260106 | Security: SEGV on unknown address with javascript url and __proto__ | $1,000 | 2016-10-02 |
260105 | Heap-use-after-free in xsltApplySequenceConstructor | $1,000 | 2016-10-02 |
261171 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
260375 | Heap-buffer-overflow in WebCore::Element::recalcStyle | $1,000 | 2016-10-02 |
259859 | Heap-use-after-free in content::RenderViewHostManager::ShutdownRenderViewHostsInSiteInstance | - | 2016-10-02 |
259669 | Security: Drag-drop an image to the desktop: adds executable file to the desktop | - | 2016-10-02 |
259389 | Heap-buffer-overflow in WebCore::parseDimension | - | 2016-10-02 |
259366 | Security: JSON.stringify does not do cross context check. | - | 2016-10-02 |
258771 | Lax permissions on the password database | - | 2016-10-02 |
258723 | Security: JPEG info leak | - | 2016-10-02 |
260087 | Heap-use-after-free in WebCore::IdTargetObserverRegistry::removeObserver | - | 2016-10-02 |
259951 | Heap-use-after-free in WebCore::RenderStyle::fontDescription | - | 2016-10-02 |
258419 | Heap-use-after-free in WebCore::CachedResource::cancelTimerFired | - | 2016-10-02 |
38066 | Exploit.IFrame.Gen | - | 2016-10-02 |
37876 | Issue when having saved password and favourite in the favourites bar | - | 2016-10-02 |
38194 | bypass the popblock | - | 2016-10-02 |
37841 | ĂÂżĂŸĂÂČĂÂÔöĂÂŽĂ”ĂÂœ chrome.exe | - | 2016-10-02 |
37840 | ĂÂżĂŸĂÂČĂÂÔöĂÂŽĂ”ĂÂœ chrome.exe | - | 2016-10-02 |
37826 | Need to merge fix for https://bugs.webkit.org/show_bug.cgi?id=35621 / ZDI-CAN-688 | - | 2016-10-02 |
37657 | Will not block all cookies when you select block all cookies | - | 2016-10-02 |
37479 | Merge http://trac.webkit.org/changeset/53442 | - | 2016-10-02 |
37447 | Google Chrome OCX Automatic Download | - | 2016-10-02 |
37383 | javascript: url with a leading NULL byte can bypass cross origin protection. | $1,000 | 2016-10-02 |
37362 | Security: Ogg Vorbis: Random crashes when playing .ogg | - | 2016-10-02 |
37310 | Crash in media::FFmpegDemuxer::~FFmpegDemuxer() | - | 2016-10-02 |
37201 | Omnibox visual spoofing with Japanese Maru | - | 2016-10-02 |
37827 | Need to merge fix for https://bugs.webkit.org/show_bug.cgi?id=35598 / ZDI-CAN-704 | - | 2016-10-02 |
37190 | Security: WebSocket: WebCore::String::isEmpty ReadAV@Arbitrary | - | 2016-10-02 |
37184 | Security: ff_vorbis_floor1_render_list ReadAV@Arbitrary (multiple stacks) | - | 2016-10-02 |
37176 | Security bugs for $500 each. | - | 2016-10-02 |
37061 | WebCore::SVGUseElement::updateContainerOffsets ExecAV@Arbitrary (1dc75f12fe3750aa1828ea20506a5d54) | $500 | 2016-10-02 |
37007 | Bypass unsafe file types dialog using extra dots at end of file name. | - | 2016-10-02 |
36976 | WebCore::SVGAnimationElement::calculatePercentFromKeyPoints ReadAV@NULL (00939658970e30ddcc2953e88ebb851d) | - | 2016-10-02 |
36774 | The 1 second timeout on safebrowsing get hash might be exploitable | - | 2016-10-02 |
36772 | Security: HTTP AUTH dialog spoofing using long subdomains (Windows Only) | - | 2016-10-02 |
36770 | HTTPS server can cause us to bypass certificate checking with NSS. | - | 2016-10-02 |
36715 | Phishing site seems to be able to bypass Chrome's phish warning page | - | 2016-10-02 |
36553 | Information Disclosure in "Web Data" | - | 2016-10-02 |
36277 | Passwords may be easily seen. | - | 2016-10-02 |
35994 | Security Issue Firefox 3.0.17 & Skype Add-on & Google Gmail | - | 2016-10-02 |
35979 | Security: Opening a malformed XML file causes a segmentation fault in xmlParseGetLasts. | - | 2016-10-02 |
35943 | [MD audit] HandleGetShaderSource Integer Underflow | - | 2016-10-02 |
35942 | [MD audit] DrawElements Signed Integer Vulnerability | - | 2016-10-02 |
35941 | [MD audit] GenGLObjects Buffer Overflow | - | 2016-10-02 |
35938 | [MD audit] DeleteGLObjects Buffer Overflow | - | 2016-10-02 |
35937 | [MD audit] GPU Signed Relatie Call Vulnerability | - | 2016-10-02 |
35934 | [MD audit] GPU Signed Relative Jump Vulnerability | - | 2016-10-02 |
35932 | [MD audit] GPU Signed Jump Vulnerability | - | 2016-10-02 |
35931 | [MD audit] Command Buffer Service Integer Overflow | - | 2016-10-02 |
35732 | Security: Renderer segfault when a malformed png file is loaded. | $500 | 2016-10-02 |
35649 | embed bug | - | 2016-10-02 |
35408 | Pls Help Google Chrome Bug | - | 2016-10-02 |
35936 | [MD audit] GPU Signed Call Vulnerability | - | 2016-10-02 |
35168 | Crash when clicking long URL with unknown scheme | - | 2016-10-02 |
35079 | Stale pointer in WebKit with captions | - | 2016-10-02 |
34834 | SSL error reported in Chrome v.4.0.249.78 (36714); OK on Firefox v.3.5.7 and I.E. v.8.0.6001.18702 | - | 2016-10-02 |
35366 | [MD audit] DOM tree node reference errors when manipulating DOM tree inside certain callbacks | - | 2016-10-02 |
34978 | WebCore::Document::recalcStyleSelector+0x7c | $500 | 2016-10-02 |
34765 | error en google mail de chrome | - | 2016-10-02 |
34800 | Security bug found in 4.0.249.78 | - | 2016-10-02 |
34710 | [MD audit] out-of-bounds array access in worker_process_host.cc | - | 2016-10-02 |
34566 | Security: WebCore::FEMorphology::apply memmove ReadAV@NULL (ec3ed2d76f7904e1c4df8ea3b1dd07e6) | - | 2016-10-02 |
34498 | Navigating to a cached page can result in accessing a destroyed HTMLInputElement [CVE-2010-0052] | - | 2016-10-02 |
34495 | Crash in XMLTokenizer::popCurrentNode if window.close() is called during parsing [CVE-2010-0048] | - | 2016-10-02 |
34414 | Regression:m7: Chrome Popup Blocker ByPass | - | 2016-10-02 |
34760 | I/O errors | - | 2016-10-02 |
34782 | Browser hangs | - | 2016-10-02 |
34721 | Long string in alert() 100% CPU DoS | - | 2016-10-02 |
278912 | Heap-buffer-overflow in WebCore::Element::recalcStyle | $2,000 | 2016-10-02 |
279263 | use-after-free in ColorChooserDialog::DidCloseDialog | $1,000 | 2016-10-02 |
278908 | Heap-use-after-free in WebCore::XMLDocumentParser::append | $1,000 | 2016-10-02 |
279286 | ASSERT: Bad cast from CSSInitialValue to CSSValueList., UNKNOWN in WebCore::CSSValue::isCFCSSValueList | - | 2016-10-02 |
279277 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | $2,000 | 2016-10-02 |
278676 | Heap-buffer-overflow in content::SiteIsolationPolicy::ShouldBlockResponse | - | 2016-10-02 |
278366 | Security: Page can DDOS and crash browser: while (1) window.open() | - | 2016-10-02 |
277656 | ASSERT: isDocumentLifecycleObserver()ASAN:SIGSEGV, UNKNOWN in WebCore::DocumentLifecycleNotifier::notifyDocumentWasDisposed | - | 2016-10-02 |
276368 | Heap-use-after-free in ppapi::proxy::PluginResource::NotifyInstanceWasDeleted | $1,000 | 2016-10-02 |
276339 | Use-after-free in content::WebPluginDelegateImpl::NativeWndProc | - | 2016-10-02 |
275803 | Heap-buffer-overflow on icu_46::CharsetRecog_UTF_32_BE::getChar | - | 2016-10-02 |
275590 | Heap-buffer-overflow in media::AudioBuffer::ReadFrames | - | 2016-10-02 |
276111 | ASSERTION FAILED: splineIndex < m_keySplines.size(), UNKNOWN in WebCore::SVGAnimationElement::calculatePercentForSpline | - | 2016-10-02 |
274843 | CORS-enabled image should fail to load when redirected with CORS failure. | - | 2016-10-02 |
274658 | Heap-use-after-free in PluginPlaceholder::ReplacePlugin | - | 2016-10-02 |
276106 | ASSERTION FAILED: actualInfo->derefObjectFunction == info.derefObjectFunction, UNKNOWN in WebCore::V8HTMLElement::createWrapper | - | 2016-10-02 |
276042 | Use-after-free in views::HWNDMessageHandler::_ProcessWindowMessage | - | 2016-10-02 |
275223 | Heap-use-after-free in WebCore::EditCommandComposition::~EditCommandComposition | - | 2016-10-02 |
273734 | Heap-use-after-free in WebCore::SharedStyleFinder::canShareStyleWithElement | - | 2016-10-02 |
273732 | Use-after-free in WebCore::GraphicsLayer::setContentsTo | - | 2016-10-02 |
272954 | Heap-use-after-free in WebCore::SpaceSplitString::set | - | 2016-10-02 |
272786 | Use-after-free in WebCore::TimerBase::stop | $2,000 | 2016-10-02 |
274020 | Security: Blocked popups can navigate anywhere once unblocked | - | 2016-10-02 |
274408 | Security: Cross-origin information should not be available via JavaScript. | - | 2016-10-02 |
271782 | Security: Incognito mode state not necessarily encrypted properly | - | 2016-10-02 |
272072 | Regression: 301 redirect to data: URLs works | - | 2016-10-02 |
271221 | Heap-use-after-free in WebCore::StylePendingImage::data | - | 2016-10-02 |
271161 | Heap-use-after-free in WebCore::AudioDSPKernelProcessor::reset | $500 | 2016-10-02 |
271130 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::CompositeEditCommand::cloneParagraphUnderNewElement | - | 2016-10-02 |
271939 | Heap-use-after-free in xsltApplySequenceConstructor | $1,000 | 2016-10-02 |
271235 | ASSERTION FAILED: index < static_cast<unsigned>(length()), UNKNOWN in WebCore::TextIterator::characterAt | - | 2016-10-02 |
270272 | Heap-use-after-free in WebCore::Node::compareDocumentPositionInternal | - | 2016-10-02 |
270758 | Heap-use-after-free in WebCore::HRTFElevation::calculateKernelsForAzimuthElevation | $500 | 2016-10-02 |
269753 | Heap-use-after-free in webkitOfflineAudioContext | $500 | 2016-10-02 |
268565 | Security: use-after-free Speech with changing of the page | $500 | 2016-10-02 |
269837 | Heap-buffer-overflow in util::to_uint16_t | - | 2016-10-02 |
269709 | Wild-access in WTF::HashTable<WebCore::RenderObject *,WTF::KeyValuePair<WebCore::RenderObject *,WebCore::FilterEffe | - | 2016-10-02 |
269835 | Heap-buffer-overflow in office::doc::BxPap::Init | - | 2016-10-02 |
268365 | Heap-use-after-free in std::pair<WTF::KeyValuePair<WTF::StringImpl*, WebCore::Element*>*, bool> WTF::HashTable<WTF::StringI | - | 2016-10-02 |
267824 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
267068 | Heap-use-after-free in WebCore::HTMLFormControlsCollectionV8Internal::indexedPropertyGetterCallback | - | 2016-10-02 |
34151 | ChromeFrame: cookie policy not honored in chrome Frame | - | 2016-10-02 |
34135 | Browser process crash (CHECK failure) in TabStripModel::GetContentsAt(int) const | - | 2016-10-02 |
33906 | Why that | - | 2016-10-02 |
33881 | Security Bug | - | 2016-10-02 |
33876 | Security: LocalStorage Cross Domain Denial of Service Attack | - | 2016-10-02 |
33873 | Confirm Close | - | 2016-10-02 |
33995 | Bug ?? | - | 2016-10-02 |
33870 | VKontakte Checker | - | 2016-10-02 |
33869 | VKontakte Tools | - | 2016-10-02 |
33864 | chrome an chromium bug with flash | - | 2016-10-02 |
33834 | MISTAKE (BĂ
ÂĂÂD) | - | 2016-10-02 |
33952 | Infinite redirects with long URL can cause browser process OOM. | - | 2016-10-02 |
33872 | Chromepad | - | 2016-10-02 |
33830 | Confirm Close | - | 2016-10-02 |
33817 | ĂÂĂÂÞñĂÂșĂ° ĂÂżĂÂĂž ĂŸĂÂĂÂșĂ»ĂÂĂÂĂ”ĂÂœĂžĂž | - | 2016-10-02 |
33791 | Trouble when opening a downloadable link | - | 2016-10-02 |
33738 | r | - | 2016-10-02 |
33736 | 333 | - | 2016-10-02 |
33729 | chrome an chromium bug with flash | - | 2016-10-02 |
33831 | some parameters not working | - | 2016-10-02 |
33678 | y | - | 2016-10-02 |
33664 | XSS Filter can disable legitimate code, creating vulnerabilities in otherwise safe webpages | - | 2016-10-02 |
33607 | Security: SSL with Chrome using googlewave.com on Chromium | - | 2016-10-02 |
33572 | Security: "Harmful websites" are allowed to initiate downloads without user intervention. | - | 2016-10-02 |
33508 | Https issue | - | 2016-10-02 |
33445 | STS design questions around probing what sites a user has been to | - | 2016-10-02 |
33391 | Script tags are copied and pasted into xml, making cross-domain attacks possible | - | 2016-10-02 |
33695 | Chrome problem. | - | 2016-10-02 |
33053 | Use of stale HTMLImageElement pointer in JSHTMLFormElement::nameGetter | - | 2016-10-02 |
32856 | Script tags are copied and pasted, making cross-domain attacks possible | - | 2016-10-02 |
33324 | New windows opened within ChromeFrame in full tab mode don't use the host network stack | - | 2016-10-02 |
32718 | Security: Cross-domain bug in password manager | $500 | 2016-10-02 |
32558 | auto text | - | 2016-10-02 |
32457 | Security: WebKit Bug 33802 - WebCore::RenderMenuList::setText ExecAV@Arbitrary (fe810d95ab2c1eef13e951397ed944ce) | - | 2016-10-02 |
32455 | ValidityState can hold a stale pointer to control | - | 2016-10-02 |
32309 | Stylesheet URL property leaks redirection target | - | 2016-10-02 |
32207 | The CLD (Compact Language Detection) code is run in the browser, it should run in the renderer. | - | 2016-10-02 |
32014 | [MD audit] [clipboard] Type confusion possible in Linux clipboard implementation | - | 2016-10-02 |
31953 | Resolve URL Before Proxy | - | 2016-10-02 |
32915 | [MD audit] [Window Sandbox] CrossCallParamsEx::CreateFromBuffer() integer overflow | - | 2016-10-02 |
31935 | appcache: https servers shouldn't be able to store no-store pages from other servers | - | 2016-10-02 |
31880 | [MD audit] [plugins] Sandbox Violation: Raw pointer from renderer manipulated in plugin process | - | 2016-10-02 |
31568 | Need to merge WebKit fix for ZDI-CAN-632 to Beta branch | - | 2016-10-02 |
31554 | Invalid Read (possible code execution): Empty name parameter passed to v8::internal::LoadIC::Load() | - | 2016-10-02 |
31542 | Use after free crash in RTL text handling | - | 2016-10-02 |
31517 | ChildProcessSecurityPolicy::CanRequestURL recusion stack exhaustion in URL parsing with nested protocols | - | 2016-10-02 |
31364 | [MD audit] [IPC] problems calling resize() on vectors with no sanitization | - | 2016-10-02 |
31307 | [MD audit] [RPC] More errors deserializing SkBitmaps!! | - | 2016-10-02 |
31298 | [MD audit] [RPC] Integer overflow in clipboard image deserialization | - | 2016-10-02 |
31293 | Audio TAG MP3 plays noise burst at beginning | - | 2016-10-02 |
31267 | Security: Popup & Focus URL Hijacking from ha.ckers.org, exploit works with chrome autodownload | - | 2016-10-02 |
31144 | warn when downloading common Linux package files such as .deb | - | 2016-10-02 |
31943 | Bypass of HTML5 iframe sandbox attribute (can set window.top.location) | - | 2016-10-02 |
31692 | Bug 33266 - WebCore::InlineFlowBox::determineSpacingForFlowBoxes ReadAV@NULL (43c64e8abbda6766e5f5edbd254c2d57) | - | 2016-10-02 |
30972 | Google Chrome XSS through MS Word Script Execution Object | - | 2016-10-02 |
31009 | [MD audit] [V8]: integer errors lead to dangerous crashes in memory allocators | - | 2016-10-02 |
31012 | [MD audit] [3d] | - | 2016-10-02 |
30937 | Possible to execute script on unpermitted domains using chrome.tabs.executeScript() | - | 2016-10-02 |
294242 | Url spoof with play store url | - | 2016-10-02 |
294206 | Heap-use-after-free in WebCore::IDBDatabase::transactionFinished | - | 2016-10-02 |
294202 | ASSERTION FAILED: hasRareData(), UNKNOWN in WebCore::Node::rareData | - | 2016-10-02 |
294023 | Heap-buffer-overflow in bool WebCore::SelectorChecker::checkOne<WebCore::DOMSiblingTraversalStrategy> | - | 2016-10-02 |
294464 | Heap-use-after-free in WebCore::SVGLength::SVGLength | - | 2016-10-02 |
294456 | Heap-use-after-free in WebCore::canMergeLists | $2,000 | 2016-10-02 |
293521 | Heap-use-after-free in WebCore::CSSFontSelector::dispatchInvalidationCallbacks | - | 2016-10-02 |
293127 | Use-after-free in WTF::HashTable<int,WTF::KeyValuePair<int,WTF::RefPtr<WebCore::CalculationValue> >,WTF::KeyValuePairK | - | 2016-10-02 |
292679 | Heap-use-after-free in Pickle::~Pickle | - | 2016-10-02 |
292422 | ASSERTION FAILED: m_pendingActivityCount > 0, Heap-use-after-free in WebCore::XMLHttpRequest::open | $1,000 | 2016-10-02 |
291854 | ASSERTION FAILED: !node || node->hasTagName(HTMLNames::metaTag), UNKNOWN in WebCore::TextAutosizer::detectContentType | - | 2016-10-02 |
290566 | Heap-use-after-free in WTF::equalNonNull | $1,000 | 2016-10-02 |
293707 | ASSERTION FAILED: !value || value->isValueList(), UNKNOWN in WebCore::FontFace::createCSSFontFace | - | 2016-10-02 |
293534 | Heap-use-after-free in WebCore::Document::updateLayout | $3,000 | 2016-10-02 |
290165 | ASSERTION FAILED: !needsLayout(), UNKNOWN in WebCore::RenderTableSection::paint | $500 | 2016-10-02 |
290163 | Heap-use-after-free in WebCore::InputMethodContext::selectedSegment | - | 2016-10-02 |
289680 | Heap-buffer-overflow in PL_strdup | - | 2016-10-02 |
289648 | Security: work around user gesture requirement | - | 2016-10-02 |
288977 | Security: Insecure root-privileged file touch in /home/chronos by activate_date_spring.conf | - | 2016-10-02 |
288797 | Heap-use-after-free in WebCore::TextFieldInputType::updateInnerTextValue | - | 2016-10-02 |
290396 | Heap-use-after-free in WebCore::FrameLoader::load | - | 2016-10-02 |
288771 | Heap-use-after-free in WebCore::SVGMatrixV8Internal::rotateMethodCallback | - | 2016-10-02 |
288761 | Heap-use-after-free in WebCore::Document::updateLayout | - | 2016-10-02 |
286975 | Heap-use-after-free in WebCore::Node::containsIncludingHostElements | $2,000 | 2016-10-02 |
286621 | Heap-use-after-free in BubbleGtk::Close | - | 2016-10-02 |
286617 | Use-after-free in WebCore::RenderObject::previousInPreOrder | - | 2016-10-02 |
286444 | Crash due to a bug in CoreText with some Arabic strings on Mac OS 10.8-10.8.4 and iOS 6 | - | 2016-10-02 |
286414 | Heap-use-after-free in WTF::KeyValuePair<WebCore::Resource*, WTF::RefPtr<WebCore::ResourceTimingInfo> >::~KeyValuePair | $1,000 | 2016-10-02 |
286368 | ASSERT: Bad cast from Element to HTMLDetailsElement., UNKNOWN in Bad cast from Element to HTMLDetailsElement | - | 2016-10-02 |
288754 | Security: OOB in xfer32 in SKIA | - | 2016-10-02 |
285783 | Heap-buffer-overflow in indic_ot_reorder | - | 2016-10-02 |
285578 | Heap-use-after-free in gpu::CommandBufferHelper::~CommandBufferHelper | - | 2016-10-02 |
285380 | Heap-use-after-free in content::QuotaDispatcherHost::RequestQuotaDispatcher::DidFinish | - | 2016-10-02 |
284792 | FileAPIMessageFilter::OnOpenFile opens files with greater permissions than checked | - | 2016-10-02 |
284786 | Heap-use-after-free in content::WebAudioSourceProviderImpl::provideInput | $500 | 2016-10-02 |
284785 | Heap-use-after-free in WebCore::ConvolverNode::tailTime | $500 | 2016-10-02 |
285787 | Heap-use-after-free in WebCore::ApplyBlockElementCommand::rangeForParagraphSplittingTextNodesIfNeeded | $1,000 | 2016-10-02 |
285742 | Heap-use-after-free in void url_parse:: | - | 2016-10-02 |
282925 | ASSERTION FAILED: !needsLayout(), UNKNOWN in WebCore::RenderSVGResourceClipper::applyClippingToContext | $500 | 2016-10-02 |
282923 | Heap-use-after-free in webrtc::voe::Channel::SendRTCPPacket | - | 2016-10-02 |
282922 | Heap-use-after-free in WebCore::HTMLMediaElement::parseAttribute | - | 2016-10-02 |
282738 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in WebCore::InlineTextBox::constructTextRun | - | 2016-10-02 |
282736 | Javascript execution bug introduced with Chrome 29.0.1547.57 | $1,000 | 2016-10-02 |
284532 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::ViewportStyleResolver::getViewportLengthValue | - | 2016-10-02 |
280352 | ASSERTION FAILED: !node || node->hasTagName(HTMLNames::tdTag) || node->hasTagName(HTMLNames::thTag), UNKNOWN in WebCore::AccessibilityTable::isDataTable | - | 2016-10-02 |
282425 | Heap-use-after-free in WebCore::RenderLayer::renderer | - | 2016-10-02 |
281256 | Address bar spoofing with window.open() + 204 No Content | $2,000 | 2016-10-02 |
280729 | Security: Linux HID flaws | - | 2016-10-02 |
280552 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
280512 | Possible to hide current address by going to "tel:" link and then a "#" link | - | 2016-10-02 |
280470 | Security: Closing a webview while it is loading crashes the OS sessions. | - | 2016-10-02 |
281480 | Heap-buffer-overflow in WebCore::ReverbConvolverStage::ReverbConvolverStage | $500 | 2016-10-02 |
280170 | Heap-use-after-free in WebRtcNetEQ_RecInRTPStruct | - | 2016-10-02 |
280128 | ChromeView segfaults writing illegally during Vellamo test with drawPosTextH | - | 2016-10-02 |
282088 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | $1,000 | 2016-10-02 |
279643 | Heap-use-after-free in cricket::StreamSelector::Matches | - | 2016-10-02 |
279642 | Heap-use-after-free in non-virtual thunk to cricket::TransportChannelProxy::OnMessage | - | 2016-10-02 |
279640 | UNKNOWN in extract_image_data | - | 2016-10-02 |
279639 | Heap-use-after-free in cricket::Connection::local_candidate | - | 2016-10-02 |
30794 | Out of bounds read when processing SVG feColorMatrix filter | - | 2016-10-02 |
30682 | Disable the null encryption and weak encryption TLS/SSL cipher suites | - | 2016-10-02 |
30660 | window.open() Method Javascript Same-Origin Policy Violation | $1,000 | 2016-10-02 |
30659 | Security: restrict sqlite functions in the function authorizer | - | 2016-10-02 |
30525 | Merge HTMLParser security fix from WebKit | - | 2016-10-02 |
30510 | Security: invalid pointer access when calling HTML5 Web Database REGEXP() function with just one argument | - | 2016-10-02 |
30146 | chrome.tabs.executeScriptInTab allows running script in the gallery | - | 2016-10-02 |
30080 | Extension pop-up page is loaded into main window | - | 2016-10-02 |
30078 | Web Workers abuse - opt in required? | - | 2016-10-02 |
29932 | Security: Websockets - malformed URL freezes browser | - | 2016-10-02 |
29920 | Referer: header is sent when redirect from https to http | - | 2016-10-02 |
30079 | Security SafeBrowsingService pure virtual function call and memory corruption | - | 2016-10-02 |
29854 | Security: WebKit Bug 32316 - WebCore::RenderObject::arenaDelete ExecAV@??? (292164e5b2ee939ff3ddf062439c2a3e) | - | 2016-10-02 |
29828 | Security: sandbox bypass due to directory traversal opening Web Database files | - | 2016-10-02 |
29645 | Prevent exposing autocomplete values via Javascript | - | 2016-10-02 |
29577 | Crash on complicated @font-face rule | - | 2016-10-02 |
29543 | Bug | - | 2016-10-02 |
29914 | DNS queries not forwarded through SOCKS v5 proxies | - | 2016-10-02 |
29657 | [MD audit] [NPAPI] Unsafe use of raw pointers between processes | - | 2016-10-02 |
29292 | HTTPS pages contain warning about not being secure. | - | 2016-10-02 |
28811 | Security: WebKit Bug 31886 - Notification::Notification m_presenter reuse of freed memory | - | 2016-10-02 |
28804 | [MD audit] [Window Sandbox] PreProcessName() Race Condition | - | 2016-10-02 |
28798 | [MD audit] [Window Sandbox] Integrity Level Race Condition | - | 2016-10-02 |
28606 | Security: Chrome/chromium crash in Skia (CSS) due to flashplugin crash | - | 2016-10-02 |
28582 | Out-of-bounds read in memcpy() upon one line CSS - sometimes OOM too | - | 2016-10-02 |
29294 | Security: What about support for the Green Address Bar? (SSL EV...) | - | 2016-10-02 |
28880 | Security: Crash in WebCore/platform/graphics/chromium/FontLinux.cpp:355 (WebCore::TextRunWalker::setupFontForScriptRun) | - | 2016-10-02 |
28566 | Security: Crash when opening a corrupted GIF image | - | 2016-10-02 |
28449 | Linear gradient on a table row crashes Chromium | - | 2016-10-02 |
28360 | Security: Chromium/chrome crash in WebCore::RenderMarquee::computePosition | - | 2016-10-02 |
28346 | Security: net::HttpStreamParser::DoReadBodyComplete OOM browser crash using Content-Length | - | 2016-10-02 |
28250 | Chrome/chromium crash in Skia (memset) due to excessive stroke | - | 2016-10-02 |
28043 | Security: LocalStorage does not account the key strings in the quota enforcement | - | 2016-10-02 |
28015 | Security: notifications can pop-up unsolicited windows | - | 2016-10-02 |
28574 | Security: Memory corruption in WebCore::ResourceLoader | - | 2016-10-02 |
27916 | Bounds error in skAlphaRuns causes renderer hang | - | 2016-10-02 |
27544 | HTML notifications should only allow http URLs as content (or not have elevated privileges for data: / javascript:) | - | 2016-10-02 |
27501 | Security: Bad reference counting in WTF:: PassRefPtr leads to use after free | - | 2016-10-02 |
26771 | Let users choose the default privacy behaviour (like address bar and other stuff ... ) IMPORTANT !!! | - | 2016-10-02 |
26770 | change default beaviour of bar: let choose users about their privacy chroium privacy | - | 2016-10-02 |
26585 | Security: Flash does not lose focus, which allows things like key logging | - | 2016-10-02 |
26179 | Security: Chromium bug for gears fts2 security vulnerability | - | 2016-10-02 |
28014 | Security: crash when requestPermission() called | - | 2016-10-02 |
27509 | Security: HttpStreamParser::DoReadBodyComplete buffer overflow. | - | 2016-10-02 |
24733 | Browser crash in icu processing text from Japanese page | - | 2016-10-02 |
26129 | Security: MSVR report: Chrome Frame allows x-domain data theft in IE | $500 | 2016-10-02 |
24375 | Unbounded read (possible write) in SDCH header parsing | - | 2016-10-02 |
23979 | Security: add other common HTML extensions to the dangerous extensions list | - | 2016-10-02 |
23693 | Security: sanitize URLs better before creating desktop shortcuts | - | 2016-10-02 |
24646 | Security: Skia memory corruption with x<0 in SkA*_Blitter::blitH | - | 2016-10-02 |
25578 | No more symbolic links in the .app (en.lproj -> en_US.lproj) | - | 2016-10-02 |
24486 | Chrome does not checksum downloaded .bdic files; Leads to crashes, possible exploits. | - | 2016-10-02 |
22846 | ChromeFrame does not respect IE Privacy features | - | 2016-10-02 |
23188 | Gears DLL is not marked at NX compatible | - | 2016-10-02 |
22115 | Two pages munged together if an anchor is clicked during unload | - | 2016-10-02 |
22721 | Security: Chrome Frame 301/302 redirect URL spoofing | - | 2016-10-02 |
23189 | avcodec-52.dll is not marked NX, SafeSEH or DBCompat | - | 2016-10-02 |
23006 | Security: Chrome Frame links circumvent IE8's SmartScreen | - | 2016-10-02 |
22451 | Use-after-free in IPC::Channel::ChannelImpl::ProcessOutgoingMessages() in UtilityProcessHostTest.ExtensionUnpacker | - | 2016-10-02 |
21354 | ISO-2022-CN and ISO-2022-CN-Ext are not supported leading to a potential XSS attack | - | 2016-10-02 |
21338 | Same Origin Policy Bypass via getSVGDocument() method. | $500 | 2016-10-02 |
21489 | Linux create fail for /tmp/chrome_shutdown_ms.txt in mixed user environment | - | 2016-10-02 |
21770 | Security: ParseFTPList buffer fencepost, integer underflow | - | 2016-10-02 |
21771 | Security: ParseFTPList integer underflow | - | 2016-10-02 |
21385 | No prompt when installing extension from odd content type | - | 2016-10-02 |
21242 | Merge webkit.org@48142 to mstone-3 | - | 2016-10-02 |
21238 | security: Content-Type: application/rss+xml being rendered as active content | - | 2016-10-02 |
21128 | XMLHttpRequest allows loading from another origin | - | 2016-10-02 |
309452 | Heap-use-after-free in WebCore::CSSSelectorList::selectorAt | - | 2016-10-02 |
309453 | Heap-use-after-free in WebCore::RenderBlockFlow::computeBlockDirectionPositionsForLine | - | 2016-10-02 |
309201 | Heap-buffer-overflow in WebCore::RenderView::positionDialog | - | 2016-10-02 |
308988 | Use-after-free in v8::HandleScope::HandleScope | - | 2016-10-02 |
307159 | Response splitting with 302 redirects allows chrome sync session fixation | $1,337 | 2016-10-02 |
306346 | Heap-use-after-free in WebCore::ResourceLoader::requestSynchronously | - | 2016-10-02 |
306694 | Crash in WebKit::WebHelperPluginImpl::closeHelperPlugin() | - | 2016-10-02 |
305951 | Security: Don't send encrypted extensions (Channel ID, NPN,OBC) when server certificate is untrusted | $1,000 | 2016-10-02 |
305904 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
305368 | Use-after-free in printing::PrintingContextWin::AskUserForSettings | - | 2016-10-02 |
306802 | Heap-buffer-overflow in WebCore::Font::characterRangeCodePath | - | 2016-10-02 |
306803 | Heap-use-after-free in content::RenderViewImpl::OnMessageReceived | - | 2016-10-02 |
306255 | content_shell crash with --dump-render-tree and non-ASCII content | - | 2016-10-02 |
305278 | Heap-use-after-free in WebCore::HTMLMediaElement::contextDestroyed | - | 2016-10-02 |
305220 | TLS session caching occurs before certificate validation | $500 | 2016-10-02 |
305080 | Heap-use-after-free in WebCore::XMLHttpRequest::~XMLHttpRequest | - | 2016-10-02 |
304967 | Use-after-free in content::GpuChannelHost::Send | - | 2016-10-02 |
305350 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGTransform>::detachWrapper | - | 2016-10-02 |
304787 | Heap-use-after-free in content::PluginURLFetcher::OnReceivedData | $500 | 2016-10-02 |
304547 | Security: popups opened in fullscreen mode are opened as popunders | - | 2016-10-02 |
304398 | WebRTCIdentityStore should delete expired identities | - | 2016-10-02 |
305279 | Heap-use-after-free in WebCore::GraphicsLayer::setContentsClippingMaskLayer | - | 2016-10-02 |
304791 | Multiple libvpx potential security issues | - | 2016-10-02 |
303927 | Use after free with new media::ScopedPtrAVFreeFrame | - | 2016-10-02 |
303657 | Heap-use-after-free in WebCore::HTMLFormElement::submit | - | 2016-10-02 |
303477 | ASSERTION FAILED: !node || node->isTextNode(), UNKNOWN in WebCore::RenderBlock::updateFirstLetter | - | 2016-10-02 |
303476 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGNumber>::detachWrapper | - | 2016-10-02 |
303232 | ASSERT: Bad cast from Event to GestureEvent., UNKNOWN in Bad cast from Event to GestureEvent | - | 2016-10-02 |
304226 | Security: Address bar spoofing on Android with window.open() + 204 No Content | - | 2016-10-02 |
303772 | Heap-use-after-free in WebCore::SliderThumbElement::dragFrom | - | 2016-10-02 |
302539 | Heap-buffer-overflow in ssl3_HandleHandshakeMessage | - | 2016-10-02 |
301941 | ASSERTION FAILED: npObject, UNKNOWN in content::NPObjectProxy::NPNEvaluate | - | 2016-10-02 |
301196 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in WebCore::InlineTextBox::paint | - | 2016-10-02 |
300892 | Heap-use-after-free in WebCore::Document::updateHoverActiveState | - | 2016-10-02 |
302724 | Content Script Shared Memory Buffer is writable | - | 2016-10-02 |
302810 | ASSERT: Bad cast from Event to TouchEvent., UNKNOWN in Bad cast from Event to TouchEvent | - | 2016-10-02 |
302007 | Security: Chrome can be easily made to stop working | - | 2016-10-02 |
299892 | HTTP 1xx response handling code allows a website to read memory from the main process' heap. | $4,000 | 2016-10-02 |
299835 | libjpeg_turbo huffval infoleak | - | 2016-10-02 |
299803 | Heap-use-after-free in WebCore::RenderLayerModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
298660 | Sparse file confuses temporary storage quota | - | 2016-10-02 |
297976 | Heap-buffer-overflow in bool WebCore::SelectorChecker::checkOne<WebCore::DOMSiblingTraversalStrategy> | - | 2016-10-02 |
300129 | Heap-use-after-free in content::RenderViewHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
299993 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
297556 | Heap-use-after-free in content::IndexedDBBackingStore::Transaction::Begin | - | 2016-10-02 |
297478 | Heap-use-after-free in WebCore::HTMLFormElement::submit | $2,000 | 2016-10-02 |
296690 | UNKNOWN in WebKit::WebSpeechRecognitionHandle::operator WTF::PassRefPtr<WebCore::SpeechRecognition> | $1,000 | 2016-10-02 |
296276 | Heap-use-after-free in WebCore::SVGMatrixV8Internal::aAttributeSetterCallback | - | 2016-10-02 |
296268 | Heap-use-after-free in WebCore::accumulateDocumentTouchEventTargetRects | - | 2016-10-02 |
297718 | HTML generated by coping url in address bar should url-encode the url | - | 2016-10-02 |
296804 | Heap-use-after-free in webrtc::voe::Channel::SendRTCPPacket | - | 2016-10-02 |
295725 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGMatrix>::detachWrapper | - | 2016-10-02 |
295338 | ASSERTION FAILED: !object || object->isLayerModelObject(), UNKNOWN in WebKit::LinkHighlight::computeEnclosingCompositingLayer | - | 2016-10-02 |
295010 | Heap-use-after-free in WebCore::RenderObject::childAt | $2,000 | 2016-10-02 |
294687 | Heap-use-after-free in task_manager::ExtensionProcessResource::GetProfileName | - | 2016-10-02 |
294505 | ASSERTION FAILED: actualInfo->derefObjectFunction == info.derefObjectFunction, UNKNOWN in WebCore::V8IDBCursor::createWrapper | - | 2016-10-02 |
296003 | Heap-buffer-overflow in void std::__final_insertion_sort<WebCore::RenderTableCell**, bool | - | 2016-10-02 |
295695 | Security: Show javascript prompt over interstitial page | - | 2016-10-02 |
20450 | Chromium shouldn't allow XHR to local directories | - | 2016-10-02 |
20336 | Security: ensure proper escaping, filtering of user inputs in paths, login data for FTP | - | 2016-10-02 |
20931 | chrome.tabs.update should not allow navigation to javascript: URLs w/o permission | - | 2016-10-02 |
20318 | Security: do not auto-complete URLs with cloaked credentials | - | 2016-10-02 |
19505 | Mixed content flash not causing mixed content warnings | - | 2016-10-02 |
19340 | Themes from URLs without the ".crx" file extension install without prompt | - | 2016-10-02 |
19334 | test | - | 2016-10-02 |
19316 | Security: download shelf question for themes from untrusted locations is not honest | - | 2016-10-02 |
19212 | Security: script injection possible in JSON.parse; will lead to XSS in some web apps | - | 2016-10-02 |
19158 | libxml2 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3529 | - | 2016-10-02 |
20334 | Security: restrict IPs, ports for PASV ftp mode | - | 2016-10-02 |
20233 | Crash potentially due to resource exhaustion | - | 2016-10-02 |
18682 | Extensions privileges granted to process that calls window.open | - | 2016-10-02 |
18672 | yuv_row_linux.cc clip() DCHECK too conservative? | - | 2016-10-02 |
18639 | Crash [@ 0xffffffff] | - | 2016-10-02 |
18009 | Security: Investigate NTLM reflection vulnerability | - | 2016-10-02 |
17655 | Security: Bypass pop-up blocker using javascript: url in a pop-up. | - | 2016-10-02 |
16535 | Security: terminate busy loops on page transitions | - | 2016-10-02 |
16413 | Security: Redirected XHR includes custom headers, CSRF risk | - | 2016-10-02 |
18803 | Avast can't scan all files of chrome's cache: password protected | - | 2016-10-02 |
15701 | XSS issue due to the lack of support for ISO-2022-KR | - | 2016-10-02 |
15556 | innerHTML applies meta/link/title tags before getting commited. | - | 2016-10-02 |
14508 | Security: browser crash with memmove() memory corruption upon large chunked encoding chunk size | - | 2016-10-02 |
14211 | Reproducible browser crash when quickly scrolling wide page horizontally | - | 2016-10-02 |
13997 | Clicking an external link in an extension page shouldn't reuse the same process. | - | 2016-10-02 |
15766 | Security: focus() selective keystroke redirection | - | 2016-10-02 |
14719 | Security: possible memory corruption in v8 regex execution engine | - | 2016-10-02 |
12617 | Starting a hiden download can allow attacker to determine how long the browser stays open. | - | 2016-10-02 |
12523 | Crash - Menu::RunMenuAt(int,int) | - | 2016-10-02 |
12307 | Subtle mixed content bugs | - | 2016-10-02 |
12303 | Chrome falls back to DIRECT connections once all proxies have failed. | - | 2016-10-02 |
12810 | Renderer can crash browser through OOM using document.title | - | 2016-10-02 |
13029 | NIL | - | 2016-10-02 |
12591 | Popup blocker bypass/open webpage in default browser using WMP Active-X | - | 2016-10-02 |
11776 | Security: Linux Chromium config directory is world/group-readable, including cookies | - | 2016-10-02 |
11739 | V8Proxy::ToNativeObjectImpl ASSERT(MaybeDOMWrapper(object)); | - | 2016-10-02 |
11545 | Extensions can be loaded by web content | - | 2016-10-02 |
11308 | ReadAV [ARBITRARY]@chrome!NPAPI::PluginInstance::NPP_DestroyStream+0x111 | - | 2016-10-02 |
11205 | CoInitialize called in renderer (before sandbox lockdown) | - | 2016-10-02 |
11178 | New Layout test failures for WebKit merge 42932:42994 | - | 2016-10-02 |
12142 | Crash when proxy responds to CONNECT request with Content-Length: 0 | - | 2016-10-02 |
11934 | Crash: Alert box in event listeners | - | 2016-10-02 |
9760 | pasting "( ĂŻÂœÂ„ĂÂĂŻÂœÂ„)ĂŻÂŸÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂ@ ĂŻÂœÂŒĂŻÂœÂźĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂœÂ°ĂŻÂœÂ°ĂŻÂœÂ°ĂŻÂŸÂ" to address bar causes full crash | - | 2016-10-02 |
9860 | ChromeHTML URI handler vulnerability | - | 2016-10-02 |
10957 | UXSS sharing window.external among frames | - | 2016-10-02 |
10869 | Buffer overflow in browser process while de-serializing SkBitmap (heap overwrite) | - | 2016-10-02 |
10736 | SkMask::computeImageSize() integer overflow | - | 2016-10-02 |
9877 | Security: cross domain thefts via CSS string property injection | - | 2016-10-02 |
10996 | Security: job object based restrictions no longer seem to be enforced | - | 2016-10-02 |
9303 | Security: possible use-after-free in OpenTypeUtilities.cpp | - | 2016-10-02 |
9608 | An HTTP response with code 401 and header with name="WWW-Authenticate" value="" crashes browser | - | 2016-10-02 |
9019 | zdi-can-464: malformed svglist parsing code execution | - | 2016-10-02 |
8757 | Cross-origin XMLHttpRequest is always allowed | - | 2016-10-02 |
8706 | Mixed content warning can be removed | - | 2016-10-02 |
8473 | Fix CONNECT requests with user-cancelled auth | - | 2016-10-02 |
8198 | Need to upgrade ICU in third_party | - | 2016-10-02 |
319117 | Master bug for Mobile Pwn2Own 2013 exploit from Pinkie Pie | - | 2016-10-02 |
319040 | Heap-buffer-overflow in WebCore::Element::pseudoStyleCacheIsInvalid | - | 2016-10-02 |
318791 | Security: Crash in aura::Window::NotifyWindowHierarchyChangeAtReceiver | - | 2016-10-02 |
319125 | Security: ClipboardHostMsg_WriteObjectsAsync allows to escape the sandbox | - | 2016-10-02 |
317999 | Security: Integer overflow leading to exploitable buffer overflow on 32-bit when parsing encrypted mp4 | - | 2016-10-02 |
317284 | ASSERTION FAILED: width == frameRect.width(), UNKNOWN in WebCore::WEBPImageDecoder::applyPostProcessing | - | 2016-10-02 |
317819 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlockFlow::createLineBoxes | - | 2016-10-02 |
317734 | Disabling filters over IPC for M32 | - | 2016-10-02 |
317485 | Use-after-free from SVGMatrixTearOff | - | 2016-10-02 |
317423 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
317286 | Stack-buffer-overflow in content::MakeWebMouseWheelEvent | - | 2016-10-02 |
318577 | Heap-use-after-free in WebCore::V8SVGTransform::resolveWrapperReachability | - | 2016-10-02 |
317913 | Heap-use-after-free in ChromeDownloadManagerDelegate::OnDownloadTargetDetermined | - | 2016-10-02 |
315889 | Security: ASAN heap-use-after-free in AnimationController::endAnimationUpdate | $3,000 | 2016-10-02 |
317210 | Heap-use-after-free in WebCore::RenderText::firstAbstractInlineTextBox | - | 2016-10-02 |
317097 | ASSERTION FAILED: m_context->document().documentElement() != m_context, Heap-use-after-free in WebCore::SVGTransformV8Internal::angleAttributeGetterCallback | - | 2016-10-02 |
316697 | Missing Skia cls for M32 to complete safe SVG communication over IPC | - | 2016-10-02 |
316339 | Heap-buffer-overflow in sk_getMetrics_glyph_00 | - | 2016-10-02 |
316298 | Security: Bad cast in ToRenderWidgetHostViewAura in web_contents_view_aura.cc | - | 2016-10-02 |
316032 | HPKP Pin-Sets set over headers are appended without a uniqueness check | - | 2016-10-02 |
317173 | CHECK failure in CHECK(p->IsSmi()) failed: ../../v8/src/objects-debug.cc(59) | - | 2016-10-02 |
317211 | Heap-buffer-overflow in PL_strdup | - | 2016-10-02 |
317174 | Heap-buffer-overflow in PORT_Alloc_Util | - | 2016-10-02 |
314469 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::doApply | $2,000 | 2016-10-02 |
314402 | UNKNOWN in WebCore::computeShapePaddingBounds | - | 2016-10-02 |
314225 | Heap-buffer-overflow in Null_Cipher | - | 2016-10-02 |
315842 | Heap-use-after-free in WebCore::HTMLTreeBuilder::adjustedCurrentStackItem | $2,000 | 2016-10-02 |
313939 | Security: Cross-origin information disclosure through createMediaElementSource and OfflineAudioContext | $4,000 | 2016-10-02 |
313743 | Heap-use-after-free in extensions::ExtensionAPI::SplitDependencyName | - | 2016-10-02 |
313529 | Heap-use-after-free in WebCore::Node::containsIncludingShadowDOM | - | 2016-10-02 |
313435 | Security: Prerendered pages can add incorrect alias URLs and intercept future navigations to them | - | 2016-10-02 |
313399 | Security: backport ARM uaccess fix | - | 2016-10-02 |
313005 | Heap-use-after-free in WebCore::Element::focus | - | 2016-10-02 |
312689 | ChromeĂąÂÂs HSTS preloads and certificate pinning does not work for wildcard-based domains when you input a ĂąÂÂ-.ù before the actual domain name. (e.g. https://abc.def-.drive.google.com) | - | 2016-10-02 |
312639 | ASSERTION FAILED: !m_history, Heap-use-after-free in WebCore::Document::nodeChildrenWillBeRemoved | - | 2016-10-02 |
314088 | Use-after-free in content::WebPluginDelegateStub::~WebPluginDelegateStub | - | 2016-10-02 |
312210 | "Require password to wake from sleep" option does not take effect | - | 2016-10-02 |
312250 | Security: Access after the end of the buffer due to undefined behavior in Pickle::FindNext | - | 2016-10-02 |
312046 | Heap-use-after-free in content::RenderViewHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
312028 | Heap-use-after-free in WebCore::SharedStyleFinder::canShareStyleWithElement | - | 2016-10-02 |
312016 | ViewHostMsg_CreateWindow: next route_id can be taken from the wrong process | - | 2016-10-02 |
311909 | Heap-use-after-free in WebCore::RenderTextFragment::originalText | - | 2016-10-02 |
311908 | ASSERTION FAILED: !needsSectionRecalc(), Heap-use-after-free in WebCore::RenderTable::topNonEmptySection | - | 2016-10-02 |
311548 | Security: inline svg that has not been marked as laid out causes ASSERT_WITH_SECURITY_IMPLICATION | - | 2016-10-02 |
312050 | UNKNOWN in WebCore::CanvasRenderingContext2D::drawTextInternal | - | 2016-10-02 |
311036 | strongswan: CVE-2013-6075 | - | 2016-10-02 |
310259 | ASSERTION FAILED: width == frameRect.width(), UNKNOWN in WebCore::WEBPImageDecoder::applyPostProcessing | - | 2016-10-02 |
311040 | strongswan: CVE-2013-6076 | - | 2016-10-02 |
310257 | Heap-buffer-overflow in VP8LConvertFromBGRA | - | 2016-10-02 |
310794 | Security: Blocking of HTTP iframes in HTTPS pages can be circumvented by using data: urls | - | 2016-10-02 |
7986 | REGRESSION: file:// URLs can script web URLs | - | 2016-10-02 |
7713 | Unescape according to the safe browsing spec | - | 2016-10-02 |
7338 | 30x redirects silently honored in response to CONNECT | - | 2016-10-02 |
7214 | Cross-domain access to stylesheet text should not be allowed | - | 2016-10-02 |
6869 | SVG support is crashy in 2.0.157.2 | - | 2016-10-02 |
6264 | Security bug: something very wrong with same-origin checks | - | 2016-10-02 |
6062 | Chrome: Crash Report - Stack Signature: WebCore::GIFImageDecoder::haveDecodedRow | - | 2016-10-02 |
7590 | Rogue renderer can tamper with Windows. | - | 2016-10-02 |
5825 | chromehtml: Elevate on Vista if no permission to modify key | - | 2016-10-02 |
5596 | Bookmarklets clicked on new tab page execute in chrome-resource security context | - | 2016-10-02 |
5271 | Add a test for bug 2074 | - | 2016-10-02 |
5248 | cross-frame-access-protocol*.html layout tests are failing | - | 2016-10-02 |
5247 | Cross-frame-access-*-explicit-domain layout tests failing | - | 2016-10-02 |
4943 | Rogue renderer could crash other renderers / browser via stats table. | - | 2016-10-02 |
4772 | Stateless key event handling from renderer to browser | - | 2016-10-02 |
4197 | Further restrict access of file URL | - | 2016-10-02 |
4150 | Security: SwissSign Root marked for EV | - | 2016-10-02 |
3896 | Make tests for bug 2074 fix and contribute to webkit | - | 2016-10-02 |
3851 | Security: need backport of WebKit bug for v1.0 release | - | 2016-10-02 |
3823 | Security: Empty string between ISO-2022 escape sequences can be potentially exploited. Make sure we don't suffer | - | 2016-10-02 |
3645 | Security: intermittent NULL ptr crash when browser close attempted with a non-responsive tab | - | 2016-10-02 |
4387 | Security: Microsoft "feature" causes dates > December 31st 3000 to crash renderer crash | - | 2016-10-02 |
3538 | SSL CN mismatch not triggering warning | - | 2016-10-02 |
3431 | Drag & drop javascript link to Windows desktop | - | 2016-10-02 |
3275 | Security: Popup-blocker bypass using click event | - | 2016-10-02 |
3256 | Security: block windows / prompts, or disable scripting altogether, while security interstitials are displayed | - | 2016-10-02 |
3628 | Websites can spawn infinite external protocol handler popups. | - | 2016-10-02 |
3382 | V8 crashes on lots of popups. | - | 2016-10-02 |
2759 | A range of non-characters (U+FDD0 .. U+FDEF) are passed through in IsStringUTF8 | - | 2016-10-02 |
2966 | Chrome Window.open & alert DoS | - | 2016-10-02 |
2618 | Web Inspector should not rely on the untrusted page to implement escapeHTML | - | 2016-10-02 |
2579 | tab_strip_model.cc can Crash Chrome.dll | - | 2016-10-02 |
2316 | Chromium automatically continues the request for a sub-resource with a certificate error under some conditions. | - | 2016-10-02 |
2748 | Crash when doing a view-source on a https-link with invalid security certificate | - | 2016-10-02 |
2957 | Clicking "Safe Browsing diagnostic page" link broken on malware interstitial | - | 2016-10-02 |
2632 | Advisory: Google Chrome Carriage Return Null Object Memory Exhaustion Remote Dos | - | 2016-10-02 |
1488 | Google Chrome Browser Exploit | - | 2016-10-02 |
1414 | Chrome Buffer Overlow Vulnerability - "SaveAs" Function | - | 2016-10-02 |
1980 | Content-Disposition triggers buffer overflow | - | 2016-10-02 |
2074 | DBCS invalid multi-byte over-consumption leads to XSS vectors | - | 2016-10-02 |
1967 | Append .download to downloaded DLL files | - | 2016-10-02 |
1227 | Firedragging "polished" - drag an executable file to the desktop appearing to be an image | - | 2016-10-02 |
1208 | Never elide file extensions (at least in download UI) | - | 2016-10-02 |
1210 | Don't trigger buttons on second click of a double-click | - | 2016-10-02 |
213 | Denial of Service | - | 2016-10-02 |
100 | custom cursor icon rendered incorrectly | - | 2016-10-02 |
326229 | Heap-buffer-overflow in SkBicubicImageFilter::onFilterImage | - | 2016-10-02 |
326187 | UNKNOWN in SkMagnifierImageFilter::onFilterImage | - | 2016-10-02 |
326199 | Heap-buffer-overflow in SkBitmap::copyTo | - | 2016-10-02 |
325624 | ASSERTION FAILED: !object || (object->isRenderBlockFlow()), UNKNOWN in WebCore::toRenderBlockFlow | - | 2016-10-02 |
326195 | Heap-buffer-overflow in SkSrcXfermode::xfer32 | - | 2016-10-02 |
326206 | Heap-buffer-overflow in SkDilateX_SSE2 | - | 2016-10-02 |
326197 | Heap-buffer-overflow in SkDiffuseLightingImageFilter::onFilterImage | - | 2016-10-02 |
326198 | Heap-buffer-overflow in Clamp_S32_D32_nofilter_trans_shaderproc | - | 2016-10-02 |
326118 | Security: chrome: address bar spoofing in Chrome for iOS | - | 2016-10-02 |
324815 | Apps can be installed from outside CWS and from non-secure sites | - | 2016-10-02 |
324812 | Security: leaking the raw global object when passing callbacks between contexts | - | 2016-10-02 |
325071 | Use-after-free in content::WebGraphicsContext3DCommandBufferImpl::InitializeCommandBuffer | - | 2016-10-02 |
324969 | Security: Address bar spoofing in Chrome for Android | $1,000 | 2016-10-02 |
325225 | Crash on keyed load invocation | - | 2016-10-02 |
324817 | Security: Unprompted app installation allowed | - | 2016-10-02 |
324321 | Heap-use-after-free in WebCore::Document::updateLayout | - | 2016-10-02 |
324320 | ASSERTION FAILED: !tryCatch.HasCaught() || result.IsEmpty(), Heap-use-after-free in content::RenderViewHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
324323 | ASSERTION FAILED: iteration >= 0, Heap-buffer-overflow in WebCore::KeyframeAnimationEffect::PropertySpecificKeyframeGroup::sample | - | 2016-10-02 |
324324 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::removeRedundantStylesAndKeepStyleSpanInline | - | 2016-10-02 |
324530 | Heap-use-after-free in WebCore::DocumentMarkerController::removeMarkersFromList | - | 2016-10-02 |
322965 | In-page search form steals focus/navigation control from Chrome's URL bar | - | 2016-10-02 |
323969 | Attempting free in std::_Rb_tree<blink::WebFrame*, std::pair<blink::WebFrame* const, content::RenderFrameImpl*>, std::_ | - | 2016-10-02 |
323682 | Use-after-free in WebCore::SVGAnimatedProperty::detachAnimatedPropertiesForElement | - | 2016-10-02 |
323595 | Heap-buffer-overflow in SkValidatingReadBuffer::getArrayCount | - | 2016-10-02 |
322662 | Multiprofile: Screen does not lock when non-corp account is active | - | 2016-10-02 |
322891 | Heap-use-after-free in WebCore::RenderLayerScrollableArea::updateCompositingLayersAfterScroll | $2,000 | 2016-10-02 |
322554 | Heap-use-after-free in WebCore::MediaStreamAudioSourceNode::process | - | 2016-10-02 |
322527 | Incognito cookies make their way into non-incognito cookie space when using HTTPS Everywhere extension | - | 2016-10-02 |
322959 | URL Spoof Vulnerability | $500 | 2016-10-02 |
322937 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
322575 | ASSERTION FAILED: activeDuration >= 0, Heap-buffer-overflow in WebCore::KeyframeAnimationEffect::PropertySpecificKeyframeGroup::sample | - | 2016-10-02 |
321831 | UNKNOWN in SkProcCoeffXfermode::CreateProc | - | 2016-10-02 |
322195 | Heap-use-after-free in content::WebRTCIdentityServiceHost::OnRequestIdentity | - | 2016-10-02 |
321783 | dev-libs/nspr needs upgrade from upstream portage | - | 2016-10-02 |
321781 | dev-libs/nss needs upgrade from upstream portage | - | 2016-10-02 |
322348 | Heap-use-after-free in WebCore::Element::focus | - | 2016-10-02 |
321802 | Heap-buffer-overflow in SkValidatingReadBuffer::readPoint | - | 2016-10-02 |
321790 | UNKNOWN in SkValidatingReadBuffer::readString | - | 2016-10-02 |
321940 | Security: Inserting a Google account to Chrome and stealing user's private data | $5,000 | 2016-10-02 |
320762 | Heap-use-after-free in WebCore::SVGStringListV8Internal::clearMethodCallback | - | 2016-10-02 |
321037 | Heap-use-after-free in WebCore::V8SVGStringList::resolveWrapperReachability | $500 | 2016-10-02 |
321495 | Heap-use-after-free in WebCore::StyleSheetCollection::resetAllRuleSetsInTreeScope | - | 2016-10-02 |
320796 | Content-security-policy object-src: isn't applied against <param name="source"> | - | 2016-10-02 |
320239 | CHECK failure in CHECK failed: it != streams_.end() in media_stream_dispatcher_host.cc(242) | - | 2016-10-02 |
320344 | Heap-use-after-free in WebCore::ChannelProvider::provideInput | $500 | 2016-10-02 |
319860 | OOB read in V8 | - | 2016-10-02 |
319835 | OOB write in V8 (only 64bit) | - | 2016-10-02 |
319722 | Heap-buffer-overflow in v8::internal::ExternalByteArray::SetValue | - | 2016-10-02 |
319477 | clipboard.cc issues | - | 2016-10-02 |
320314 | Heap-use-after-free in autofill::PasswordAutofillAgent::DidStartProvisionalLoad | - | 2016-10-02 |
320313 | Heap-use-after-free in base::internal::Invoker<1, base::internal::BindState<base::internal::RunnableAdapter<void | - | 2016-10-02 |
319914 | Use-after-free in v8::internal::GlobalHandles::Destroy | - | 2016-10-02 |
331571 | Typing pandora.com in omnibox automatically redirects user to native app, if installed | - | 2016-10-02 |
331444 | [LangFuzz] Crash at v8::internal::StoreBuffer::Compact with invalid write | $3,000 | 2016-10-02 |
331416 | [LangFuzz] Crash on Heap with Array access/length and invalid read | $3,000 | 2016-10-02 |
331725 | Security: body of POST request initiated 302-redirect chain can be recovered by script on last page in chain using XSS Auditor | $500 | 2016-10-02 |
331790 | Security: use-after-free in content::WebContentsImpl::~WebContentsImpl | $1,000 | 2016-10-02 |
331253 | Use-after-free in v8::HandleScope::HandleScope | - | 2016-10-02 |
331389 | Heap-use-after-free in er_supported | - | 2016-10-02 |
331219 | Using a long JavaScript alert() string can hide buttons and prevention checkbox | - | 2016-10-02 |
331168 | Security: scrollbar-corner can be drawn outside the containing frame, allowing redress of parent frame. | $500 | 2016-10-02 |
331060 | Security: XSS Auditor behavior can cause leak of submitted form data because of about:blank redirection | $1,000 | 2016-10-02 |
331254 | Heap-buffer-overflow in WebCore::BisonCSSParser::parseValue | - | 2016-10-02 |
331232 | Use-after-free in WebCore::Editor::rangeOfString | - | 2016-10-02 |
330710 | UXSS can be performed because XSS Auditor processes tokens inside script tag separately | - | 2016-10-02 |
330660 | use-after-free in SpeechRecognitionBubbleView::GetAnchorRect | $500 | 2016-10-02 |
330626 | Heap-use-after-free in WebCore::RenderInline::willBeDestroyed | $2,000 | 2016-10-02 |
330750 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlockFlow::createLineBoxes | - | 2016-10-02 |
330663 | UXSS from a local MHTML file | $1,000 | 2016-10-02 |
330222 | UNKNOWN in TIntermSymbol::TIntermSymbol | - | 2016-10-02 |
330420 | ASSERTION FAILED: m_stateStack.size() == 1, Heap-use-after-free in WebCore::ScrollView::paint | $1,000 | 2016-10-02 |
329978 | AutofillHostMsg_ShowPasswordSuggestions: validate that suggestions.size() == realms.size() | - | 2016-10-02 |
330293 | UNKNOWN in SkRegion::setPath | $3,000 | 2016-10-02 |
329723 | Security: arbitrary memory read in logging::LogMessage::Init | - | 2016-10-02 |
329258 | Global-buffer-overflow in BrotliHuffmanTreeBuildImplicit | - | 2016-10-02 |
329547 | Heap-buffer-overflow in ReadHuffmanCode | - | 2016-10-02 |
329006 | ASSERTION FAILED: std::isfinite(num), Heap-buffer-overflow in SkChopCubicAt | - | 2016-10-02 |
329651 | UAF: Utterance should not keep a raw pointer to TtsMessageFilter | - | 2016-10-02 |
329254 | Global-buffer-overflow in SkMallocPixelRef::SkMallocPixelRef | - | 2016-10-02 |
329386 | Security: Handling HSTS headers effectively clobbers preloaded pins | - | 2016-10-02 |
329238 | Heap-use-after-free in WebCore::RenderBlockFlow::computeBlockDirectionPositionsForLine | - | 2016-10-02 |
328202 | Security: v8: invalid overflow checks in Zone::NewExpand() | - | 2016-10-02 |
328231 | Security: incorrect overflow check in SparseControl::StartIO() | - | 2016-10-02 |
328456 | ASSERTION FAILED: !m_deletionHasBegun, UNKNOWN in WebCore::FormAssociatedElement::formRemovedFromTree | - | 2016-10-02 |
328620 | The GPU sandbox sometimes call InitializeSandbox() with threads appearing running. | - | 2016-10-02 |
328203 | Security: WebGLRenderingContext::copyTexSubImage2D - invalid checks for overflow. | - | 2016-10-02 |
327824 | The seccomp-bpf sandbox fails silently on the GPU process with threads | - | 2016-10-02 |
327372 | Heap-buffer-overflow in SkDisplacementMapEffect::onFilterImage | - | 2016-10-02 |
327729 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGMatrix>::detachWrapper | - | 2016-10-02 |
327720 | Heap-use-after-free in chrome_browser_net::GetDataReductionRequestType | - | 2016-10-02 |
327626 | Security: RELEASE_ASSERT in SubtreeLayoutScope destructor | - | 2016-10-02 |
326860 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
326854 | Heap-use-after-free in WebCore::FormAssociatedElement::formRemovedFromTree | $1,000 | 2016-10-02 |
327065 | Heap-use-after-free in StyleResolver::applyMatchedProperties | - | 2016-10-02 |
327070 | ASSERTION FAILED: !m_hasBadParent, Heap-use-after-free in WebCore::InlineBox::nextLeafChild | - | 2016-10-02 |
339610 | Heap-use-after-free in WebCore::Canvas2DLayerBridge::freeReleasedMailbox | - | 2016-10-02 |
339498 | Heap-use-after-free in CacheCreator::DoCallback | - | 2016-10-02 |
339337 | Use RefPtr in PageWidgetDelegate and guard RenderView | - | 2016-10-02 |
339314 | Heap-use-after-free in content::VideoCaptureController::DoIncomingCapturedI420BufferOnIOThread | - | 2016-10-02 |
338532 | UNKNOWN in /usr/lib/x86_64-linux-gnu/libstdc++.so.6+0x6441f | - | 2016-10-02 |
338524 | Security: TOCTOU Bug in Windows Sandbox Handle Duplication Service | - | 2016-10-02 |
338561 | Heap-use-after-free in content::MediaStreamManager::FinalizeEnumerateDevices | - | 2016-10-02 |
338393 | Heap-use-after-free in content::GpuChannelHost::Send | - | 2016-10-02 |
338354 | Heap-use-after-free in IPC::Message::Header const* Pickle::headerT<IPC::Message::Header> | - | 2016-10-02 |
338345 | Heap-use-after-free in content::WebContentsImpl::CreateNewWindow | - | 2016-10-02 |
338538 | Security: Windows Sandbox Anonymous Kernel Object Unrestricted DACL | $3,000 | 2016-10-02 |
338464 | UaF of ColorChooserAura | - | 2016-10-02 |
338164 | Heap-use-after-free in std::_Rb_tree<std::string, std::pair<std::string const, extensions::ExtensionDownloaderDelegate::Pin | - | 2016-10-02 |
338109 | ASSERTION FAILED: !box || (box->isSVGInlineFlowBox()), UNKNOWN in WebCore::SVGRootInlineBox::layoutCharactersInTextBoxes | - | 2016-10-02 |
337882 | Security: ASAN "heap-buffer-overflow" in CallBitmapXferProc | $2,000 | 2016-10-02 |
338341 | Heap-use-after-free in content::RenderProcessHostImpl::ProcessDied | - | 2016-10-02 |
338124 | Heap-use-after-free in elapsed | - | 2016-10-02 |
337572 | Heap-use-after-free in cricket::BaseChannel::SendPacket | - | 2016-10-02 |
337561 | ASSERTION FAILED: controller->hasClientForTest(), Heap-buffer-overflow in WebCore::GeolocationClientMock::setPositionUnavailableError | - | 2016-10-02 |
337488 | Security: Even when there are certificate errors, password auto-fill (easy-fill) works | - | 2016-10-02 |
337428 | Tracking bug for internal security fixes for Chrome 32, Release 1 | - | 2016-10-02 |
337071 | UNKNOWN in NetworkASync::QueueDeletion | - | 2016-10-02 |
337727 | Heap-buffer-overflow in __gnu_cxx::new_allocator<unsigned long>::construct | - | 2016-10-02 |
337746 | Security: unicode character can create phishing-friendly address bar | $1,500 | 2016-10-02 |
337562 | Heap-use-after-free in WebCore::HTMLFormElement::removeImgElement | - | 2016-10-02 |
336436 | Heap-use-after-free in WebCore::V8SVGAnimatedRect::visitDOMWrapper | - | 2016-10-02 |
336875 | Heap-use-after-free in cc::FrameRateController::DidSwapBuffersComplete | - | 2016-10-02 |
336841 | Security: WebRequest API allows modifying details in inline extension installations | - | 2016-10-02 |
335416 | Heap-buffer-overflow in WebCore::Font::expansionOpportunityCount | - | 2016-10-02 |
335242 | Heap-buffer-overflow in setup_frame_size_with_refs | - | 2016-10-02 |
335921 | Heap-use-after-free in WebCore::AutofocusTask::performTask | - | 2016-10-02 |
334448 | Uninit memory access in CLD2 inside translate::DeterminePageLanguage | - | 2016-10-02 |
334314 | IndexedDB: Replace passing identically-sized vectors through IPC with passing pairs/tuples | - | 2016-10-02 |
334897 | Security: Windows Sandbox Named Pipe Policy Doesn't Block Relative Paths | $2,000 | 2016-10-02 |
334204 | Same-origin security issue in <video> on Android | - | 2016-10-02 |
334082 | Heap-use-after-free in plugins::PluginPlaceholder::ReplacePlugin | - | 2016-10-02 |
333885 | Stack-use-after-return in _mesa_optimize_program | - | 2016-10-02 |
334725 | Heap-use-after-free in WebCore::SpaceSplitString::set | - | 2016-10-02 |
334274 | Security: Sandbox escape due to vector length mismatch in IndexedDBHostMsg_DatabasePut IPC message | - | 2016-10-02 |
333378 | Heap-use-after-free in WebCore::ResourceFetcher::frame() | $1,000 | 2016-10-02 |
333156 | Use-after-free in WebCore::SVGAnimatedProperty::detachAnimatedPropertiesForElement | - | 2016-10-02 |
333155 | Bad cast to XPath::Filter in XPathGrammar.y | - | 2016-10-02 |
333094 | Security: Flash allows clipboard theft / manipulation for duration of session after receiving a single paste event | - | 2016-10-02 |
333058 | Security: set_state global_handles renderer crash (UAF) with Web Workers and Web SQL | $1,000 | 2016-10-02 |
333038 | Security: Sandbox escape due to vector length mismatch in ImageHostMsg_DidDownloadImage IPC message | - | 2016-10-02 |
333036 | Tracking bug for internal security fixes for Chrome 32, Release 0 | - | 2016-10-02 |
333431 | ASSERTION FAILED: !node || (node->isSVGElement()), UNKNOWN in WebCore::SVGSMILElement::connectEventBaseConditions | - | 2016-10-02 |
332677 | ASSERTION FAILED: !node || (node->isElementNode()), UNKNOWN in WebCore::toElement | - | 2016-10-02 |
332579 | Drag-and-drop files not working on Windows Aura | - | 2016-10-02 |
332957 | PartialCircularBuffer is unsafe to use across security boundaries | - | 2016-10-02 |
332675 | Use-after-free in plugins::PluginPlaceholder::UpdateMessage | - | 2016-10-02 |
345526 | UNKNOWN in v8::internal::FixedArrayBase::length | - | 2016-10-02 |
345715 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
344674 | UNKNOWN in content::TouchDispositionGestureFilter::OnGestureEventPacket | - | 2016-10-02 |
344654 | Use-after-free in net::URLRequestContextGetter::OnDestruct | - | 2016-10-02 |
345014 | Wild-access in WebCore::V8PerContextDataHolder::from | - | 2016-10-02 |
344881 | Heap-use-after-free in WebCore::SpeechSynthesis::cancel | $4,000 | 2016-10-02 |
344359 | ASSERTION FAILED: bounds.width() >= 0 && bounds.height() >= 0 && radii.width() >= 0 && radii.height() >= 0, Heap-use-after-free in WebCore::RenderBlockFlow::constructLine | - | 2016-10-02 |
344265 | Heap-use-after-free in views::TooltipManagerAura::UpdateTooltip | - | 2016-10-02 |
344186 | OOB write due to invalid bounds check in v8 | - | 2016-10-02 |
344051 | Security: dump_vpd_log can be tricked into creating a file (or corrupt non-regular file) | - | 2016-10-02 |
344492 | Heap-use-after-free in WebCore::SVGImage::setContainerSize | $1,000 | 2016-10-02 |
344360 | ASSERTION FAILED: !node || (node->isElementNode()), UNKNOWN in WebCore::RenderBlock::clone | - | 2016-10-02 |
344230 | Use-after-free in WebCore::RootInlineBox::closestLeafChildForPoint | $1,000 | 2016-10-02 |
343648 | Stack-buffer-overflow in content::DecodeAudioFileData | - | 2016-10-02 |
343582 | Use-after-free in WebCore::DocumentTimeline::createPlayer | - | 2016-10-02 |
343383 | Renderer crash / heap-use-after-free in BrowserPlugin | - | 2016-10-02 |
343265 | Heap-use-after-free in content::NavigatorImpl::NavigateToEntry | - | 2016-10-02 |
343928 | UNKNOWN in v8::internal::FixedArrayBase::length | - | 2016-10-02 |
343964 | UNKNOWN in v8::internal::FixedArray::get | - | 2016-10-02 |
343461 | Global-buffer-overflow in SkBitmap::setConfig | - | 2016-10-02 |
343661 | Security: UAF while deleting IndexedDB databases from (shared) workers | $3,000 | 2016-10-02 |
342618 | Security: UXSS via dispatchEvent on iframes (subject to some conditions) | $3,000 | 2016-10-02 |
342735 | Security: UaF in controller of color chooser | $1,000 | 2016-10-02 |
342949 | Security: Bypass extension install prompt with --install-from-webstore and --force-app-mode | - | 2016-10-02 |
343050 | Use-after-free in WebCore::FrameView::autoSizeIfEnabled | - | 2016-10-02 |
342856 | UNKNOWN in WebCore::ThreadState::visitStack | - | 2016-10-02 |
341865 | Heap-use-after-free in WebCore::FrameLoader::loadHistoryItem | - | 2016-10-02 |
342151 | Heap-use-after-free in ui::OnFileNotSelected | - | 2016-10-02 |
341093 | Heap-use-after-free in WebCore::GraphicsContext::restore | - | 2016-10-02 |
341220 | Chrome_ChromeOS: Crash Report - WebCore::KURL::init | - | 2016-10-02 |
340687 | Heap-use-after-free in WebCore::CompositedLayerMapping::~CompositedLayerMapping | - | 2016-10-02 |
340387 | Security: Unquoted path in mini_installer can lead to executing the wrong executable | - | 2016-10-02 |
340125 | CHECK failure in CHECK(is_valid) failed: ../../v8/src/v8conversions.h(107) | - | 2016-10-02 |
340124 | CHECK failure in CHECK(p->IsHeapObject()) failed: ../../v8/src/objects-debug.cc(219) | - | 2016-10-02 |
340697 | ASSERTION FAILED: m_match == Tag, Heap-buffer-overflow in WebCore::RuleSet::findBestRuleSetAndAdd | - | 2016-10-02 |
341754 | Heap-use-after-free in WebCore::WorkerThreadableWebSocketChannel::Peer::Peer | - | 2016-10-02 |
341555 | HTTP iFrame loaded into HTTPS page (Mixed active content protection bypass) | - | 2016-10-02 |
339994 | Heap-use-after-free in std::_Rb_tree<std::pair<int, media::AudioParameters>, std::pair<std::pair<int, media::AudioParameter | - | 2016-10-02 |
340001 | Heap-use-after-free in WebCore::CSSParserValueList::~CSSParserValueList | - | 2016-10-02 |
340007 | Heap-use-after-free in v8::internal::Heap::UpdateAllocationSiteFeedback | - | 2016-10-02 |
340048 | Heap-use-after-free in WebCore::V8SVGAnimatedString::visitDOMWrapper | - | 2016-10-02 |
339993 | ASSERTION FAILED: !box || (box->isSVGInlineFlowBox()), UNKNOWN in WebCore::SVGRootInlineBox::layoutCharactersInTextBoxes | - | 2016-10-02 |
339667 | Heap-use-after-free in content::BrowserMessageFilter::Send | - | 2016-10-02 |
351855 | Pwnium 4: Mali GPU driver does not mask out VM_MAYWRITE | - | 2016-10-02 |
351852 | AsyncPixelTransfersCompletedQuery does not validate shared memory offset | - | 2016-10-02 |
351811 | Security: Pwnium 4 GeoHot bug: cros-disks accepts labels, has path traversal issues. | - | 2016-10-02 |
351796 | Security: Pwnium 4 GeoHot bug: try_touch_experiment command injection | - | 2016-10-02 |
351788 | Security: Pwnium 4 GeoHot tracking bug | $150,000 | 2016-10-02 |
351787 | Pwnium 4: v8 OOB read/write with __defineGetter__ and bytesLength | - | 2016-10-02 |
351729 | Use-after-free in WebCore::RenderObject::setPreferredLogicalWidthsDirty | - | 2016-10-02 |
352043 | Chrome: Crash Report - WebCore::Resource::ResourceCallback::timerFired | - | 2016-10-02 |
351815 | Pwnium: Extension system allows compromised renderer access to crosh | - | 2016-10-02 |
351316 | Heap-use-after-free in WebCore::SMILTimeContainer::wakeupTimerFired | - | 2016-10-02 |
351504 | Heap-use-after-free in gfx::ImageSkia::operator= | - | 2016-10-02 |
351103 | sandbox::CodeGen::MergeTails (seccomp-bpf) is unsound for single-successor basic blocks | $500 | 2016-10-02 |
351314 | Heap-use-after-free in views::DesktopDispatcherClient::RunWithDispatcher | - | 2016-10-02 |
351320 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
351209 | UNKNOWN in v8::internal::MarkCompactCollector::ProcessMarkingDeque | - | 2016-10-02 |
350760 | Use-after-free in WebCore::ShadowTreeStyleSheetCollection::collectStyleSheets | - | 2016-10-02 |
350537 | Heap-use-after-free in printing::PrintViewManagerBase::ReleasePrinterQuery | - | 2016-10-02 |
350535 | Security: Callers of showModalDialog can be trivially XSSed by a cross-origin modal dialog | - | 2016-10-02 |
350863 | CHECK failure in CHECK(object->map()->IsMap()) failed: ../src/heap-inl.h(833) | - | 2016-10-02 |
350930 | Heap-use-after-free in std::_Rb_tree<std::pair<int, media::AudioParameters>, std::pair<std::pair<int, media::AudioParameter | - | 2016-10-02 |
350686 | Heap-use-after-free in webFrame | - | 2016-10-02 |
350509 | ASSERTION FAILED: !value || (value->isPrimitiveValue()), UNKNOWN in WebCore::StyleBuilder::applyProperty | - | 2016-10-02 |
350434 | [LangFuzz] Crash with jump to invalid address | $2,000 | 2016-10-02 |
350533 | Origin confusion bug in QUIC | - | 2016-10-02 |
350055 | Heap-use-after-free in WebCore::CSSParserValueList::~CSSParserValueList | - | 2016-10-02 |
349903 | ASSERTION FAILED: !object || (object->isListBox()), UNKNOWN in WebCore::HTMLSelectElement::listBoxDefaultEventHandler | $1,500 | 2016-10-02 |
349898 | Security: Integer Overflows in CharacterData::deleteData & CharacterData::replaceData | $1,500 | 2016-10-02 |
349465 | UNKNOWN in v8::internal::JSFunction::context | - | 2016-10-02 |
350518 | Security: WinSock initialized in Utility Process. | - | 2016-10-02 |
350100 | Heap-use-after-free in content::IndexedDBFactory::Open | - | 2016-10-02 |
349079 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
348952 | Insecure marked as secure when restored from session | - | 2016-10-02 |
348682 | ASSERTION FAILED: to <= m_run.length(), UNKNOWN in WebCore::HarfBuzzShaper::setDrawRange | - | 2016-10-02 |
348581 | Dynamically created script tags disregard Content-Type and X-Content-Type-Options | - | 2016-10-02 |
348550 | ParseHSTSHeader should tolerate trailing ";" | - | 2016-10-02 |
348333 | Security: base::SHA1HashBytes produces wrong SHA1 hash when |len| >= 4GB | - | 2016-10-02 |
348332 | Security: Integer overflow allocating shared memory in SoftwareFrameManager::SwapToNewFrame() | $3,000 | 2016-10-02 |
349135 | Heap-use-after-free in cc::internal::TaskGraphRunner::SetTaskGraph | - | 2016-10-02 |
348175 | Tracking bug for internal security fixes for Chrome 33, Release 1 | - | 2016-10-02 |
347909 | CHECK failure in CHECK(value->IsHeapObject()) failed: ../src/objects-debug.cc(295) | - | 2016-10-02 |
348319 | UNKNOWN in v8::internal::MemoryChunk::heap | - | 2016-10-02 |
347720 | Security: Protocol handler UI does not filter "protocol" and "title" strings | - | 2016-10-02 |
347543 | CHECK failure in CHECK(object_size <= Page::kMaxRegularHeapObjectSize) failed: ../src/ia32/macro-assembler-ia32.cc(15 | - | 2016-10-02 |
347532 | CHECK failure in CHECK(isolate->microtask_pending()) failed: ../src/execution.cc(358) | - | 2016-10-02 |
347528 | CHECK failure in CHECK(IsNativeContext()) failed: ../src/contexts.h(462) | - | 2016-10-02 |
347302 | Chrome_Linux: Crash Report - content::MediaStreamDispatcherHost::OnEnumerateDevices | - | 2016-10-02 |
347846 | Bypassing policies set by removing battery (can be fixed) | - | 2016-10-02 |
347284 | Scroll pointer iteration during tree sync is a really bad idea | - | 2016-10-02 |
347177 | Use-after-free in media::GpuVideoDecoder::Initialize | - | 2016-10-02 |
346997 | Security: Self signed assets don't fail. | - | 2016-10-02 |
346744 | Security: download attribute allows download without user interaction | - | 2016-10-02 |
346599 | Skia refcounted objects are held in non-refcounted places | - | 2016-10-02 |
346557 | Heap-use-after-free in autofill::PasswordGenerator::Generate | - | 2016-10-02 |
347262 | UNKNOWN in v8::internal::Map::instance_descriptors | - | 2016-10-02 |
346343 | NO STACK | - | 2016-10-02 |
346192 | Heap-use-after-free in WebCore::SVGFontFaceElement::associatedFontElement | $1,000 | 2016-10-02 |
346135 | Security: html files from file URLs can read data from other file URLs via drag-and-drop | $1,000 | 2016-10-02 |
346110 | Heap-use-after-free in get | - | 2016-10-02 |
346489 | Heap-buffer-overflow in VariablePacker::searchColumn | - | 2016-10-02 |
346141 | Global-buffer-overflow in GetVisitor | - | 2016-10-02 |
345820 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
345929 | mirrorv2 crashes when nobody is receiving | - | 2016-10-02 |
345959 | Integer overflows in StringBuilder | - | 2016-10-02 |
358254 | Heap-buffer-overflow in UDataMemory_normalizeDataPointer_46 | - | 2016-10-02 |
358059 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
358057 | UNKNOWN in v8::internal::Simulator::DecodeType3 | - | 2016-10-02 |
358038 | Security: UAF/Crash in (websockets) onsentdata/reset with web and shared workers combined | $2,000 | 2016-10-02 |
357712 | Heap-use-after-free in void std::basic_string<unsigned short, base::string16_char_traits, std::allocator<unsigned short> >: | - | 2016-10-02 |
358471 | importScripts ignores script-src CSP | - | 2016-10-02 |
357382 | Security: ProcessManager::GetExtensionForRenderViewHost determines extension ID unsafely | - | 2016-10-02 |
357292 | Use-after-free in WebCore::GraphicsLayer::updateContentsRect | - | 2016-10-02 |
357669 | Heap-use-after-free in WebCore::FrameSelection::setSelection | - | 2016-10-02 |
357242 | Heap-use-after-free in WebCore::RenderBox::enclosingFloatPaintingLayer | - | 2016-10-02 |
357174 | Heap-use-after-free in WebCore::MemoryCache::insertInLRUList | - | 2016-10-02 |
357452 | Heap-use-after-free in WebCore::RenderTreeBuilder::createRendererForElementIfNeeded | - | 2016-10-02 |
357269 | Cross-origin request credentials are not removed properly in WebCore::DocumentThreadableLoader::loadRequest | - | 2016-10-02 |
356736 | minijail should signal failure when it cannot change user/group | - | 2016-10-02 |
356690 | Heap-use-after-free in WebCore::RenderObject::childAt | $1,000 | 2016-10-02 |
356653 | Security: Use after free in StyleEngine::createSheet | $3,000 | 2016-10-02 |
356652 | Extensions can modify the appearance of the Chrome Web Store | - | 2016-10-02 |
356540 | Heap-use-after-free in content::BufferedResourceLoader::Stop | - | 2016-10-02 |
356517 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::removeRedundantStylesAndKeepStyleSpanInline | - | 2016-10-02 |
357173 | Use-after-free in WebCore::AsyncCallStackTracker::didRemoveEventListener | - | 2016-10-02 |
356235 | Untrusted synthetic gestures received in the browser are not verified | - | 2016-10-02 |
356220 | NO STACK | - | 2016-10-02 |
356211 | RETRY_AFTER_GC Failure Leak | - | 2016-10-02 |
356181 | Security: WebGL texImage2D can enable out-of-bounds memory access on Android | - | 2016-10-02 |
356095 | Heap-use-after-free in WebCore::HTMLBodyElement::insertedInto | $2,000 | 2016-10-02 |
356352 | ASSERTION FAILED: !webMediaPlayer(), Heap-use-after-free in blink::WebMediaPlayerClientImpl::load | $1,000 | 2016-10-02 |
355586 | UNKNOWN in int v8::internal::FlexibleBodyVisitor<v8::internal::NewSpaceScavenger, v8::internal::JSObject::BodyD | - | 2016-10-02 |
355438 | Use-after-free in WebCore::RenderBlockFlow::checkFloatsInCleanLine | - | 2016-10-02 |
355303 | UAF from RefCount Leak in Length::operator= | - | 2016-10-02 |
355036 | Security: integer overflow validating size in mojo::internal::FixedBuffer::Allocate | - | 2016-10-02 |
354931 | Security: UAF in NotifyAndDeleteIfDone/browser process crash related to WebSQL transactions in a Web Worker | - | 2016-10-02 |
354878 | Heap-use-after-free in WebCore::RenderText::firstAbstractInlineTextBox | - | 2016-10-02 |
355373 | ASSERTION FAILED: !widget || (widget->isPluginView()), UNKNOWN in WebCore::CompositedLayerMapping::updateGraphicsLayerConfiguration | - | 2016-10-02 |
354297 | use-of-uninitialized-memory in WebCore::RenderStyle::fontDescription, may cause use-after-free or some such | - | 2016-10-02 |
353895 | Heap-use-after-free in WebCore::StylePendingImage::cssValue | - | 2016-10-02 |
353894 | Heap-use-after-free in WebCore::StyleEngine::createSheet | - | 2016-10-02 |
354669 | Chrome_ChromeOS: Crash Report - net::QuicConnection::CanWrite | - | 2016-10-02 |
354058 | UNKNOWN in DecodeContextMap | - | 2016-10-02 |
353579 | Security: Android show full security for weak DH groups. | - | 2016-10-02 |
353577 | ASSERTION FAILED: cc < codePointsNumber, UNKNOWN in WebCore::MediaQueryTokenizer::nextToken | - | 2016-10-02 |
353224 | libwidevinecdm.so text section is writeable (rwx) | - | 2016-10-02 |
353058 | Heap-buffer-overflow in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
353035 | Heap-use-after-free in WebCore::MemoryCache::evict | - | 2016-10-02 |
353013 | Security: admin.google.com should have HSTS preloaded | - | 2016-10-02 |
352982 | CHECK failure in CHECK(object->map()->IsMap()) failed: ../src/heap-inl.h(818) | - | 2016-10-02 |
353621 | Use-after-free in WebCore::InspectorCSSAgent::collectAllDocumentStyleSheets | - | 2016-10-02 |
352941 | Use-after-free in WebCore::StyleSheetContents::startLoadingDynamicSheet | - | 2016-10-02 |
352929 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
352851 | Security: UaF in SpeechRecognitionBubbleImpl::~SpeechRecognitionBubbleImpl | $1,000 | 2016-10-02 |
352447 | Security: Use a narrowwhitelist for VFS names | - | 2016-10-02 |
352429 | Security: Junction Point directory traversal vulnerability - pwn2own 2014 | - | 2016-10-02 |
352395 | Pwn2Own (3/13/2014): Compromised renderers can set arbitrary clipboard formats | - | 2016-10-02 |
352380 | Geolocation permission is remembered on an HTTP site | - | 2016-10-02 |
352905 | Security: Incorrect origin shown on modal windows opened by sub-frames of chrome.google.com/webstore | - | 2016-10-02 |
352369 | Pwn2own (3/13/2014): VUPEN exploit. | - | 2016-10-02 |
352181 | ASSERTION FAILED: !CustomElementCallbackDispatcher::inCallbackDeliveryScope(), UNKNOWN in WebCore::CustomElementMicrotaskDispatcher::doDispatch | - | 2016-10-02 |
352178 | Heap-use-after-free in WebCore::SVGFontFaceElement::associatedFontElement | - | 2016-10-02 |
352083 | Security: Chrome for Android - URL bar spoof | $3,000 | 2016-10-02 |
352374 | Pwn2own (3/13/2014): Use-after-free in bindings | - | 2016-10-02 |
364511 | Buffer overflow vulnerability in glibc | - | 2016-10-02 |
364405 | Security: input events to plugins bypass regular user gesture tracking | - | 2016-10-02 |
364365 | Crash while creating a SPDY session | - | 2016-10-02 |
364066 | ASSERTION FAILED: !activeAnimations || !activeAnimations->isAnimationStyleChange(), Heap-use-after-free in WebCore::CSSAnimations::AnimationEventDelegate::maybeDispatch | - | 2016-10-02 |
364065 | SEGV in media::InMemoryUrlProtocol::Read | $1,000 | 2016-10-02 |
363873 | ASSERTION FAILED: !object || (object->isBox()), UNKNOWN in WebCore::CompositedLayerMapping::updateGraphicsLayerGeometry | $3,000 | 2016-10-02 |
363841 | Hosted app alerts from iframes show title of app, not domain of iframe | - | 2016-10-02 |
363631 | ASSERTION FAILED: !value || (value->isPrimitiveValue()), UNKNOWN in WebCore::StyleBuilderFunctions::applyValueCSSPropertyFontVariant | - | 2016-10-02 |
363390 | Security: 64-bit may leak kernel addresses via LDT | - | 2016-10-02 |
362887 | Security: SSL CRL Vulnerability in Android Chrome | - | 2016-10-02 |
362865 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
362898 | Heap-use-after-free in WebCore::Resource::checkNotify | - | 2016-10-02 |
362558 | Heap-use-after-free in content::VideoCaptureImpl::InitOnIOThread | - | 2016-10-02 |
362480 | Use-after-free in WebCore::Chrome::notifyPopupOpeningObservers | - | 2016-10-02 |
362110 | ASSERTION FAILED: positionOffset <= node->length(), UNKNOWN in WebCore::updatePositionAfterAdoptingTextReplacement | - | 2016-10-02 |
362109 | ASSERTION FAILED: i <= length, UNKNOWN in WebCore::WindowFeatures::WindowFeatures | - | 2016-10-02 |
361933 | Global-buffer-overflow in v8::internal::VisitorDispatchTable<void | - | 2016-10-02 |
362762 | Import qcms buffer overflow fix | - | 2016-10-02 |
362310 | Use-after-free in WebCore::MutableStylePropertySet::mergeAndOverrideOnConflict | - | 2016-10-02 |
360784 | Use-after-free in WebCore::RenderTextFragment::originalText | - | 2016-10-02 |
361608 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
360733 | Heap-buffer-overflow in v8::internal::Simulator::HandleRList | - | 2016-10-02 |
360798 | Security: openssl info leak | - | 2016-10-02 |
360595 | Heap-buffer-overflow in bits_to_runs | - | 2016-10-02 |
360448 | Eavesdrop on the user speech - abusing the old speech API | - | 2016-10-02 |
360431 | Heap-buffer-overflow in getNextNormalizedChar | - | 2016-10-02 |
360430 | ASSERTION FAILED: index < TypedArrayBase<T>::m_length, UNKNOWN in WebCore::FEDisplacementMap::applySoftware | - | 2016-10-02 |
360429 | ASSERTION FAILED: actualInfo->derefObjectFunction == wrapperTypeInfo.derefObjectFunction, UNKNOWN in WebCore::V8HTMLElement::createWrapper | - | 2016-10-02 |
360408 | Stack-buffer-overflow in opj_read_bytes_LE | - | 2016-10-02 |
360403 | Heap-buffer-overflow in bool WebCore::CSSTokenizer::parseURIInternal<unsigned char, unsigned short> | - | 2016-10-02 |
360478 | UNKNOWN in void v8::internal::String::Visit<v8::Utf8LengthHelper::Visitor, v8::internal::ConsStringCaptureOp> | - | 2016-10-02 |
360433 | Heap-use-after-free in uprv_strdup_46 | - | 2016-10-02 |
360504 | Security: I accidentially disabled relro on chromeos arm m35. | - | 2016-10-02 |
360481 | ASSERTION FAILED: !m_clusterStack.isEmpty(), UNKNOWN in WebCore::FastTextAutosizer::currentCluster | - | 2016-10-02 |
360205 | Heap-buffer-overflow in opj_mct_decode | - | 2016-10-02 |
360171 | ASSERTION FAILED: !m_clusterStack.isEmpty(), UNKNOWN in WebCore::FastTextAutosizer::currentCluster | - | 2016-10-02 |
360163 | Heap-use-after-free in WebCore::BreakingContext::commitAndUpdateLineBreakIfNeeded | - | 2016-10-02 |
360345 | Heap-use-after-free in media::DecryptingDemuxerStream::Stop | - | 2016-10-02 |
360344 | UNKNOWN in opj_j2k_read_SQcd_SQcc | - | 2016-10-02 |
360214 | Heap-use-after-free in WebCore::DocumentMarkerController::removeMarkersFromList | - | 2016-10-02 |
359525 | CHECK failure in CHECK(size_in_bytes <= kMaxBlockSize) failed: ../src/spaces.cc(2378) | - | 2016-10-02 |
360053 | Global-buffer-overflow in CFX_FaceCache::RenderGlyph | - | 2016-10-02 |
359134 | UNKNOWN in v8::internal::MemoryChunk::IsFlagSet | - | 2016-10-02 |
359130 | Heap-use-after-free in WebCore::SpeechSynthesisUtterance::startTime | - | 2016-10-02 |
359802 | ZDI-CAN-2245: Google Chrome ImageData Signedness Error Remote Code Execution VulnerabilityImageData Signedness Error Remote Code Execution Vulnerability | - | 2016-10-02 |
359454 | Security: Integer overflow allocating shared memory in AudioInputRendererHost::OnCreateStream | $3,000 | 2016-10-02 |
359602 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
358571 | Security: appengine.google.com has wildcard but not include_subdomains | - | 2016-10-02 |
358667 | Heap-buffer-overflow in void WebCore::CSSTokenizer::parseIdentifier<unsigned char> | - | 2016-10-02 |
358960 | Heap-use-after-free in content::MediaStreamAudioSinkOwner::OnReadyStateChanged | - | 2016-10-02 |
358813 | Heap-use-after-free in WebCore::Scrollbar::gestureEvent | - | 2016-10-02 |
369760 | UNKNOWN in content::WAVEDecoder::ReadChunkHeader | - | 2016-10-02 |
369759 | ASSERTION FAILED: positionOffset <= node->length(), UNKNOWN in WebCore::updatePositionAfterAdoptingTextReplacement | - | 2016-10-02 |
369621 | Crash in content::RendererClipboardWriteContext::WriteBitmapFromPixels | $500 | 2016-10-02 |
369615 | ASSERT !m_paintStateIndex failure in ~GraphicsContext, missing a restore(). | - | 2016-10-02 |
369848 | double-click allows to steal form history | - | 2016-10-02 |
369808 | Heap-use-after-free in void WebCore::ImageDecodingStore::insertCacheInternal<WebCore::ImageDecodingStore::ImageCacheEntry, | - | 2016-10-02 |
369517 | UNKNOWN in SkPath::isRectContour | - | 2016-10-02 |
369525 | ASSERTION FAILED: static_cast<FileError::ErrorCode>(code) != FileError::ABORT_ERR, Heap-use-after-free in v8::internal::GlobalHandles::Node::Release | $1,000 | 2016-10-02 |
368980 | Heap-buffer-overflow in ff_er_frame_end | - | 2016-10-02 |
369519 | ASSERTION FAILED: !tryCatch.HasCaught() || result.IsEmpty(), Heap-use-after-free in WebCore::InlineBox::dirtyLineBoxes | - | 2016-10-02 |
369127 | UNKNOWN in v8::internal::NoBarrier_Load | - | 2016-10-02 |
368551 | Use-after-free in WebCore::ResourcePtrBase::setResource | - | 2016-10-02 |
368978 | Bad-cast to WebCore::ShadowRoot from WebCore::Text;ShadowRoot.h:164:1 | - | 2016-10-02 |
368979 | UNKNOWN in v8::internal::NoBarrier_Load | - | 2016-10-02 |
367817 | Cross origin bypass with Object.observe(). | - | 2016-10-02 |
367812 | Security: AppCache allows MITM of same-origin shared hosting | - | 2016-10-02 |
367764 | UNKNOWN in SkValidatingReadBuffer::readString | - | 2016-10-02 |
367567 | Security: Any extension can debug any other extension (e.g. crosh) | $1,500 | 2016-10-02 |
367985 | UNKNOWN in android::MPEG4Source::stop | - | 2016-10-02 |
367544 | UNKNOWN in CJBig2_GSIDProc::decode_Arith | - | 2016-10-02 |
367508 | Use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
366781 | WebVector::initialize{From} should bounds check its size parameter | - | 2016-10-02 |
366694 | UNKNOWN in opj_read_bytes_LE | - | 2016-10-02 |
366693 | Global-buffer-overflow in CJS_PublicMethods::MakeFormatDate | - | 2016-10-02 |
366692 | Heap-use-after-free in Document::title | - | 2016-10-02 |
366690 | Heap-buffer-overflow in j2k_read_ppm_v3 | - | 2016-10-02 |
366947 | PSL matching should only apply to HTML forms | - | 2016-10-02 |
366797 | Security: UAF in mojo::internal::DecodePointerRaw | - | 2016-10-02 |
366510 | Heap-use-after-free in content::RenderFrameHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
366687 | Heap-buffer-overflow in load_truetype_glyph | - | 2016-10-02 |
366685 | Heap-buffer-overflow in CPDF_ColorSpace::TranslateImageLine | - | 2016-10-02 |
366683 | UNKNOWN in libc.so.6 | - | 2016-10-02 |
366682 | UNKNOWN in CFXMEM_FixedMgr::AllocLarge | - | 2016-10-02 |
366681 | UNKNOWN in CFXMEM_FixedMgr::Realloc | - | 2016-10-02 |
366686 | Heap-buffer-overflow in j2k_read_ppm_v3 | - | 2016-10-02 |
366496 | Mobile Chrome Sync tokens used by the mobile Chrome browser can be used to push extensions. | - | 2016-10-02 |
366688 | Heap-use-after-free in CPDFSDK_Document::GetInterForm | - | 2016-10-02 |
366689 | Heap-use-after-free in opj_stream_read_data | - | 2016-10-02 |
366182 | Use-after-free in std::_For_each<std::_Deque_unchecked_iterator<std::_Deque_val<std::_Deque_simple_types<appcache::App | - | 2016-10-02 |
365359 | Malicious page can escalate to content script privilege level when content script modifies page DOM | $1,000 | 2016-10-02 |
366251 | Security: CSP policy matching can be used as a timing oracle | - | 2016-10-02 |
365064 | Heap-use-after-free in WebCore::CompositedLayerMapping::~CompositedLayerMapping | $2,000 | 2016-10-02 |
365141 | Heap-use-after-free in media::Pipeline::StateTransitionTask | - | 2016-10-02 |
377416 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
377392 | Linux kernel futex() memory corruption vulnerability and exploit | $10,000 | 2016-10-02 |
377209 | UNKNOWN in v8::internal::MemoryChunk::heap | - | 2016-10-02 |
377193 | Heap-use-after-free in SkPathRef::resetToSize | - | 2016-10-02 |
377290 | UNKNOWN in v8::internal::Map::instance_type | - | 2016-10-02 |
376951 | Security: webgl draw buffers extension can expose unitialized video memory to webpage | $2,000 | 2016-10-02 |
376802 | Heap-buffer-overflow in decoder_decode | - | 2016-10-02 |
376748 | Heap-use-after-free in WebCore::ImageLoader::doUpdateFromElement | - | 2016-10-02 |
377118 | Security: Close manually opened tab via scripting | - | 2016-10-02 |
376800 | Heap-buffer-overflow in WebCore::TextResourceDecoder::checkForCSSCharset | - | 2016-10-02 |
375954 | Heap-use-after-free in WebCore::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
376438 | Heap-use-after-free in nextOnLine | - | 2016-10-02 |
375672 | ThreadSanitizer reports a use-after-free in DomSerializerTests.SerializeHTMLDOMWithEmptyHead | - | 2016-10-02 |
376433 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlockFlow::createLineBoxes | - | 2016-10-02 |
374904 | ASSERTION FAILED: !node || (node->isShadowRoot()), UNKNOWN in WebCore::TextIterator::advance | - | 2016-10-02 |
374443 | Heap-buffer-overflow in v8::internal::__RT_impl_Runtime_TypedArrayInitializeFromArrayLike | - | 2016-10-02 |
374452 | Network icon should be updated when a VPN disconnects | - | 2016-10-02 |
374052 | Heap-use-after-free in SkScaledImageCache::findAndLock | - | 2016-10-02 |
373312 | Heap-buffer-overflow in WebRtcIsacfix_Decode | - | 2016-10-02 |
374497 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::spinButtonElement | - | 2016-10-02 |
374665 | Heap-use-after-free in WebCore::SQLiteStatement::prepare | - | 2016-10-02 |
374176 | Security: no javascript: url pasting protection on android | - | 2016-10-02 |
372525 | Security: heap write access due to integer overflow on bspatch implementations | - | 2016-10-02 |
372413 | UNKNOWN in CFXMEM_Page::Free | - | 2016-10-02 |
373283 | UNKNOWN in v8::internal::NoBarrier_Load | - | 2016-10-02 |
372410 | Heap-buffer-overflow in CPDF_DIBSource::TranslateScanline24bpp | - | 2016-10-02 |
372820 | ASSERTION FAILED: !value || (value->isStepsTimingFunctionValue()), UNKNOWN in WebCore::CSSToStyleMap::mapAnimationTimingFunction | - | 2016-10-02 |
372411 | Global-buffer-overflow in CJS_PublicMethods::MakeFormatDate | - | 2016-10-02 |
372110 | Heap-use-after-free in SkImageFilter::filterImage | - | 2016-10-02 |
371380 | Heap-use-after-free in opj_read_from_memory | - | 2016-10-02 |
372206 | Crash on content::WebURLLoaderImpl::cancel | - | 2016-10-02 |
371813 | Heap-use-after-free in content::ResourceDispatcher::RemovePendingRequest | - | 2016-10-02 |
371237 | Heap-buffer-overflow in SkBitmapHeap::getBitmap | - | 2016-10-02 |
371240 | Global-buffer-overflow in SkBlitter::Choose | - | 2016-10-02 |
369860 | Security: ASAN heap-use-after-free in SVGElement::propertyFromAttribute | $2,000 | 2016-10-02 |
385268 | Heap-use-after-free in WebCore::RenderBlock::computeBlockPreferredLogicalWidths | - | 2016-10-02 |
385054 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
385002 | Heap-buffer-overflow in v8::internal::Simulator::HandleRList | - | 2016-10-02 |
384890 | Heap-use-after-free in WebCore::FrameLoaderStateMachine::advanceTo | - | 2016-10-02 |
384662 | Security: Possible integer overflow in CFX_BasicArray::Append | - | 2016-10-02 |
384365 | Heap-use-after-free in chrome_pdf::PDFiumPage::GetPage | - | 2016-10-02 |
384223 | Security: http basic authentication dialog from background tab is displayed over the active tab | - | 2016-10-02 |
383939 | Heap-use-after-free in JavaObjectWeakGlobalRef::get | - | 2016-10-02 |
384891 | Heap-buffer-overflow in chrome_pdf::AlphaBlend | - | 2016-10-02 |
383725 | [PowerProfiler] Browser crashes with active timeline recording for capturing power | - | 2016-10-02 |
383777 | ASSERTION FAILED: positionOffset <= node->length() | $1,000 | 2016-10-02 |
383703 | ASSERT_WITH_SECURITY_IMPLICATION(i <= length) in WebCore::Document::processArguments | - | 2016-10-02 |
382921 | Uninitialized members in OriginChipView | - | 2016-10-02 |
382820 | Heap-buffer-overflow in CPDF_DeviceCS::TranslateImageLine | - | 2016-10-02 |
382766 | Security: never build chrome-sandbox with ASAN coverage | - | 2016-10-02 |
382667 | Security: Integer overflow from "offset + size" everywhere | - | 2016-10-02 |
383704 | ASSERT_WITH_SECURITY_IMPLICATION(i <= length) in WebCore::WindowFeatures::WindowFeatures | - | 2016-10-02 |
382260 | Heap-use-after-free in content::ThreadedDataProvider::Stop | - | 2016-10-02 |
382639 | Security: Integer overflow in fpdfsdk/include/fsdk_mgr.h | - | 2016-10-02 |
382522 | Heap-use-after-free in media::MidiManager::CompleteInitializationInternal | - | 2016-10-02 |
382513 | UNKNOWN in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
382279 | Heap-use-after-free in WebCore::HTMLFrameElementBase::openURL | - | 2016-10-02 |
382601 | Integer overflow in FX_AllocStringW | - | 2016-10-02 |
382243 | UNKNOWN in CFXMEM_FixedMgr::AllocLarge | - | 2016-10-02 |
382242 | UNKNOWN in _CMapLookupCallback | - | 2016-10-02 |
382241 | Heap-buffer-overflow in CPDF_TrueTypeFont::LoadGlyphMap | - | 2016-10-02 |
382656 | Security: Integer overflow in ./core/include/fxcrt/fx_basic.h and ./core/include/fxcrt/fx_memory.h | - | 2016-10-02 |
382606 | Security: Integer overflow in javascript/Document.cpp | - | 2016-10-02 |
382239 | Heap-buffer-overflow in opj_j2k_update_image_data | - | 2016-10-02 |
382121 | Heap-use-after-free in content::RenderFrameImpl::didFinishLoad | - | 2016-10-02 |
381808 | Security: JavaScript can detect visited links via CSS nested <a><button> + getClientRects height (OSX) | $1,000 | 2016-10-02 |
381696 | Global-buffer-overflow in CFX_Font::LoadGlyphPath | - | 2016-10-02 |
382240 | Stack-buffer-overflow in IccLib_Translate | - | 2016-10-02 |
381521 | Heap-buffer-overflow in CFX_WideString::FromUTF16LE | - | 2016-10-02 |
381534 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
381465 | Crash when legacy EVP_PKEY outlives Java wrapper on Android 4.1.2. | - | 2016-10-02 |
381200 | Security: OpenSSL CCS Vulnerability | - | 2016-10-02 |
381031 | Attempting free in CJBig2_Context::~CJBig2_Context | - | 2016-10-02 |
380885 | Security: Cache-based SOP-Bypass for Images | $2,000 | 2016-10-02 |
380723 | Heap-buffer-overflow in SkValidatingReadBuffer::readRect | - | 2016-10-02 |
381244 | Heap-buffer-overflow in void SkMatrixConvolutionImageFilter::filterPixels<UncheckedPixelFetcher, true> | - | 2016-10-02 |
380512 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
379998 | Heap-use-after-free in WebCore::V8SVGTransformList::visitDOMWrapper | - | 2016-10-02 |
379856 | Heap-use-after-free in content::PeerConnectionAudioSinkOwner::OnData | - | 2016-10-02 |
379799 | UNKNOWN in unsafe_free | - | 2016-10-02 |
379656 | Security: Integer overflow leads to buffer overflow in PDF_EncodeText | - | 2016-10-02 |
380663 | Security: Safe Browsing for Executable Files can be bypassed by using the FileSystem API | $500 | 2016-10-02 |
379458 | Heap-buffer-overflow in WebRtcIsacfix_Decode | - | 2016-10-02 |
379271 | Security: New UserGestureIndicator created for every touch event. | - | 2016-10-02 |
378782 | Heap-buffer-overflow in matroska_read_seek | - | 2016-10-02 |
378512 | Security: Clicking "export" in Certificate Viewer can cause navigation to arbitrary filesystem paths | - | 2016-10-02 |
378469 | Heap-use-after-free in WebCore::GraphicsContext::drawImage | - | 2016-10-02 |
378179 | Heap-use-after-free in cricket::ChannelManager::StopVideoCapture | - | 2016-10-02 |
378175 | Heap-buffer-overflow in SkReadBuffer::readBitmap | - | 2016-10-02 |
378167 | ASSERTION FAILED: value.isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::backgroundRepeatPropertyValue | - | 2016-10-02 |
387844 | Use-of-uninitialized-value in CPDF_StreamParser::ParseNextElement | - | 2016-10-02 |
387843 | Use-of-uninitialized-value in EvalSegmentedFn | - | 2016-10-02 |
387841 | Use-of-uninitialized-value in CPDF_DIBSource::TranslateScanline24bpp | - | 2016-10-02 |
387840 | Use-of-uninitialized-value in T1_Load_Glyph | - | 2016-10-02 |
387845 | Use-of-uninitialized-value in FPDFAPI_inflate | - | 2016-10-02 |
387842 | Use-of-uninitialized-value in aes_decrypt_nb_4 | - | 2016-10-02 |
387837 | Use-of-uninitialized-value in opj_t2_read_packet_header | - | 2016-10-02 |
387826 | Use-of-uninitialized-value in cmsXYZ2Lab | - | 2016-10-02 |
387835 | Use-of-uninitialized-value in _DrawGouraud | - | 2016-10-02 |
387834 | Use-of-uninitialized-value in CRYPT_ArcFourCryptBlock | - | 2016-10-02 |
387833 | Use-of-uninitialized-value in CPDF_Parser::LoadCrossRefV4 | - | 2016-10-02 |
387832 | Use-of-uninitialized-value in CXML_Parser::SkipLiterals | - | 2016-10-02 |
387831 | Use-of-uninitialized-value in CPDF_DeviceCS::GetRGB | - | 2016-10-02 |
387827 | Use-of-uninitialized-value in CXML_Parser::SkipLiterals | - | 2016-10-02 |
387838 | Use-of-uninitialized-value in CCodec_RLScanlineDecoder::Create | - | 2016-10-02 |
387839 | Use-of-uninitialized-value in _CompositeRow_Argb2Rgb_NoBlend | - | 2016-10-02 |
387836 | Use-of-uninitialized-value in CFX_Matrix::TransformRect | - | 2016-10-02 |
387816 | Use-of-uninitialized-value in CXML_Parser::ParseElement | - | 2016-10-02 |
387824 | Use-of-uninitialized-value in _A85Decode | - | 2016-10-02 |
387820 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
387819 | Use-of-uninitialized-value in CPDF_SimpleParser::GetWord | - | 2016-10-02 |
387818 | Use-of-uninitialized-value in CPDF_StreamParser::GetNextWord | - | 2016-10-02 |
387817 | Use-of-uninitialized-value in _FaxG4GetRow | - | 2016-10-02 |
387821 | Use-of-uninitialized-value in FXSYS_round | - | 2016-10-02 |
387815 | Use-of-uninitialized-value in CPDF_RenderStatus::GetFillArgb | - | 2016-10-02 |
387814 | Use-of-uninitialized-value in CXML_Parser::GetTagName | - | 2016-10-02 |
387813 | Use-of-uninitialized-value in CXML_Parser::SkipLiterals | - | 2016-10-02 |
387825 | Use-of-uninitialized-value in CLZWDecoder::Decode | - | 2016-10-02 |
387822 | Use-of-uninitialized-value in CXML_Parser::GetCharRef | - | 2016-10-02 |
387811 | Use-of-uninitialized-value in CStretchEngine::ContinueStretchHorz | - | 2016-10-02 |
387809 | Use-of-uninitialized-value in CPDF_SeparationCS::GetRGB | - | 2016-10-02 |
387808 | Use-of-uninitialized-value in _RGB_Blend | - | 2016-10-02 |
387807 | Use-of-uninitialized-value in FXSYS_StrToInt<int, | - | 2016-10-02 |
387806 | Use-of-uninitialized-value in CJBig2_Context::parseSegmentHeader | - | 2016-10-02 |
387805 | Use-of-uninitialized-value in CJBig2_Context::parseSegmentHeader | - | 2016-10-02 |
387803 | Use-of-uninitialized-value in CPDF_SimpleParser::ParseWord | - | 2016-10-02 |
387812 | Use-of-uninitialized-value in IccLib_Translate | - | 2016-10-02 |
387801 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
387800 | Use-of-uninitialized-value in _cmsReadHeader | - | 2016-10-02 |
387802 | Use-of-uninitialized-value in CXML_Parser::ParseElement | - | 2016-10-02 |
387798 | Use-of-uninitialized-value in CJBig2_Context::parseSymbolDict | - | 2016-10-02 |
387796 | Use-of-uninitialized-value in CFX_MapByteStringToPtr::operator | - | 2016-10-02 |
387793 | Use-of-uninitialized-value in CPDF_TrueTypeFont::LoadGlyphMap | - | 2016-10-02 |
387792 | Use-of-uninitialized-value in compareCID | - | 2016-10-02 |
387791 | Use-of-uninitialized-value in CPDF_Parser::LoadCrossRefV5 | - | 2016-10-02 |
387790 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
387789 | Use-of-uninitialized-value in CPDF_StreamParser::ReadString | - | 2016-10-02 |
387788 | Use-of-uninitialized-value in CXML_Parser::ParseElement | - | 2016-10-02 |
387786 | Use-of-uninitialized-value in CPDF_StreamParser::ReadHexString | - | 2016-10-02 |
387785 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
387797 | Use-of-uninitialized-value in tt_glyph_load | - | 2016-10-02 |
387783 | Use-of-uninitialized-value in CPDF_DataAvail::GetObject | - | 2016-10-02 |
387778 | Use-of-uninitialized-value in CXML_Parser::GetCharRef | - | 2016-10-02 |
387781 | Use-of-uninitialized-value in T1_Load_Glyph | - | 2016-10-02 |
387780 | Use-of-uninitialized-value in _FaxGetRun | - | 2016-10-02 |
387779 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
387784 | Use-of-uninitialized-value in PDF_DecodeText | - | 2016-10-02 |
387777 | Use-of-uninitialized-value in MatShaperEval16 | - | 2016-10-02 |
387776 | Use-of-uninitialized-value in CPDF_Parser::LoadCrossRefV4 | - | 2016-10-02 |
387775 | Use-of-uninitialized-value in CPDF_RenderStatus::LoadSMask | - | 2016-10-02 |
387774 | Use-of-uninitialized-value in CPDF_DataAvail::GetObject | - | 2016-10-02 |
387506 | Use-of-uninitialized-value in FXSYS_round | - | 2016-10-02 |
387782 | Use-of-uninitialized-value in CPDF_DIBSource::DownSampleScanline | - | 2016-10-02 |
387389 | Heap-use-after-free in WebCore::DocumentV8Internal::getElementByIdMethodCallbackForMainWorld | $2,000 | 2016-10-02 |
387371 | Bad-cast to gfx::MultiAnimation from gfx::ThrobAnimation;tab.cc:1096:11 | - | 2016-10-02 |
387315 | Bad-cast to WebCore::HTMLLabelElement from WebCore::SVGUnknownElement;WebNode.h:164:16 | - | 2016-10-02 |
387313 | Use-of-uninitialized-value in t1_parse_font_matrix | - | 2016-10-02 |
387211 | Bad-cast to WebCore::RenderInline from WebCore::RenderBlockFlow;RenderInline.h:195:1 | - | 2016-10-02 |
387037 | DownloadPathIsDangerous should verify that the path is a directory | - | 2016-10-02 |
387033 | Navigation bypass for web -> file | - | 2016-10-02 |
387031 | Security: V8 Array length getter override | - | 2016-10-02 |
387016 | Bad-cast to WebCore::SpeechSynthesisUtterance from WebCore::SpeechSynthesis; V8EventTargetCustom.cpp:52:5 | - | 2016-10-02 |
387470 | Heap-use-after-free in WebCore::DocumentThreadableLoader::notifyFinished | - | 2016-10-02 |
387014 | Use-of-uninitialized-value in CPDF_RenderStatus::GetStrokeArgb | - | 2016-10-02 |
387013 | Use-of-uninitialized-value in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
387011 | Use-of-uninitialized-value in CPDF_StandardSecurityHandler::GetUserPassword | - | 2016-10-02 |
387010 | Use-of-uninitialized-value in sfnt_open_font | - | 2016-10-02 |
386730 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
386729 | Use-of-uninitialized-value in CPDF_RenderStatus::GetFillArgb | - | 2016-10-02 |
386728 | Use-of-uninitialized-value in CPDF_DeviceCS::GetRGB | - | 2016-10-02 |
386034 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
386988 | Full chain exploit + sandbox escape: Array.concat -> extension install -> download exec | $30,000 | 2016-10-02 |
385691 | Bad cast from DevToolsNetworkTransactionFactory to HttpNetworkLayer | - | 2016-10-02 |
385646 | Heap-buffer-overflow in vp9_resize_frame_buffers | - | 2016-10-02 |
391570 | Stack-buffer-overflow in content::webcrypto::platform::CreatePublicKeyAlgorithm | $1,000 | 2016-10-02 |
391472 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
391470 | Use-of-uninitialized-value in CPDF_RenderStatus::DrawShading | - | 2016-10-02 |
391301 | Use-of-uninitialized-value in cc::SolidColorDrawQuad::SetNew | - | 2016-10-02 |
391023 | Uninitialized IPC message in OutOfProcessPPAPITest.ImageData | - | 2016-10-02 |
391004 | Use-of-uninitialized-value in SkUnPreMultiply::UnPreMultiplyPreservingByteOrder | - | 2016-10-02 |
391001 | Use-of-uninitialized-value in SkFlatDictionary<SkPaint, SkPaint::FlatteningTraits>::findAndReturnMutableF | $500 | 2016-10-02 |
391000 | Use-of-uninitialized-value in SkBitmap::setAlphaType | - | 2016-10-02 |
390999 | Use-of-uninitialized-value in WebCore::OpaqueRegionSkia::markRectAsNonOpaque | - | 2016-10-02 |
390997 | Use-of-uninitialized-value in FT_Outline_Get_Orientation | - | 2016-10-02 |
390973 | Use-of-uninitialized-value in IPC::ChannelPosix::ProcessOutgoingMessages | - | 2016-10-02 |
390970 | Use-of-uninitialized-value in IPC::ChannelPosix::ProcessOutgoingMessages | - | 2016-10-02 |
390945 | Use-of-uninitialized-value in put_vp8_epel16_h6v6_c | - | 2016-10-02 |
390944 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
390941 | Use-of-uninitialized-value in vp8_h_loop_filter16_c | - | 2016-10-02 |
390936 | Use-after-poison in WebCore::ThreadHeap<WebCore::FinalizedHeapObjectHeader>::addToFreeList | - | 2016-10-02 |
390928 | Heap-use-after-free in v8::internal::GlobalHandles::Create | $4,000 | 2016-10-02 |
390711 | Security: umount can be called from non-root user via fusermount | - | 2016-10-02 |
390567 | UNKNOWN in base::Time::LocalMidnight | - | 2016-10-02 |
390709 | Security: Local Priv Esc - pppd malformed config file could lead to code execution in suid binary | - | 2016-10-02 |
390601 | Use-of-uninitialized-value in CFX_WideString::InitStr | - | 2016-10-02 |
390570 | Heap-use-after-free in WebCore::MediaValues::calculateMediaType | - | 2016-10-02 |
390569 | Heap-use-after-free in WebCore::RenderBlockFlow::computeInlinePreferredLogicalWidths | - | 2016-10-02 |
390624 | Security: Extensions can spoof the list of host permissions in the permission dialog | $1,000 | 2016-10-02 |
390563 | Heap-use-after-free in content::ChildSharedBitmapManager::FreeSharedMemory | - | 2016-10-02 |
390314 | Use-of-uninitialized-value in WebCore::PositionOptions::PositionOptions | - | 2016-10-02 |
390308 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-02 |
390304 | Use-of-uninitialized-value in webrtc::BuildMediaDescription | - | 2016-10-02 |
390176 | Heap-use-after-free in WebCore::HTMLImportLoader::removeImport | - | 2016-10-02 |
389285 | Heap-use-after-free in WebCore::RenderInline::inlineElementContinuation | - | 2016-10-02 |
389316 | Use-of-uninitialized-value in WebCore::TransformationMatrix::blend | - | 2016-10-02 |
389451 | Security: SDCH dictionary URL check can be bypassed | - | 2016-10-02 |
389570 | Heap-buffer-overflow in convolveVertically_SSE2 | - | 2016-10-02 |
389573 | Use-of-uninitialized-value in v8::internal::Decoder<v8::internal::Simulator>::DecodeBranchSystemException | - | 2016-10-02 |
389595 | Use-of-uninitialized-value in void v8::internal::Simulator::AddSubHelper<long> | - | 2016-10-02 |
389734 | Security: You can spoof any domain in the URL bar | $500 | 2016-10-02 |
390069 | Use-of-uninitialized-value in read_tag_lutmABType | - | 2016-10-02 |
390174 | Heap-use-after-free in WebCore::KURL::~KURL | $2,000 | 2016-10-02 |
389574 | Global-buffer-overflow in SkBitmap::ReadRawPixels | - | 2016-10-02 |
389223 | Chromoting host ignores NAT traversal policy | - | 2016-10-02 |
389219 | Use-of-uninitialized-value in WebCore::BiquadDSPKernel::updateCoefficientsIfNecessary | $500 | 2016-10-02 |
389216 | Use-of-uninitialized-value in WebCore::AudioContext::scheduleNodeDeletion | - | 2016-10-02 |
389204 | CRASH: media::AudioRendererMixer::OnRenderError() | - | 2016-10-02 |
388771 | Heap-use-after-free in extensions::V8SchemaRegistry::GetSchema | - | 2016-10-02 |
388762 | Use-after-free in content::LegacyRenderWidgetHostHWND::UpdateParent | - | 2016-10-02 |
388759 | NO STACK | - | 2016-10-02 |
389280 | Use-of-uninitialized-value in validate_layout | - | 2016-10-02 |
388757 | Use-after-free in WebCore::RenderBlockFlow::addOverhangingFloats | - | 2016-10-02 |
388665 | Penguins Puzzle WebGL game frequent Aw Snap | $3,000 | 2016-10-02 |
388294 | Heap-use-after-free in v8::HandleScope::Initialize | $1,000 | 2016-10-02 |
388267 | Use-after-poison in WebCore::IDBDatabase::trace | - | 2016-10-02 |
388135 | Use-of-uninitialized-value in CPDF_CMap::GetNextChar | - | 2016-10-02 |
388134 | Use-of-uninitialized-value in _SetLum | - | 2016-10-02 |
388133 | Use-of-uninitialized-value in CFX_BidiChar::AppendChar | - | 2016-10-02 |
388070 | Heap-buffer-overflow in media::FFmpegDemuxer::Seek | - | 2016-10-02 |
388058 | Heap-use-after-free in cc::PictureLayerTiling::TilingEvictionTileIterator::Initialize | - | 2016-10-02 |
387861 | Use-of-uninitialized-value in FPDFAPI_FT_DivFix | - | 2016-10-02 |
387852 | Use-of-uninitialized-value in aes_decrypt_nb_4 | - | 2016-10-02 |
387860 | Use-of-uninitialized-value in FXSYS_atoi | - | 2016-10-02 |
387856 | Use-of-uninitialized-value in _JpegScanSOI | - | 2016-10-02 |
387855 | Use-of-uninitialized-value in _FaxSkipEOL | - | 2016-10-02 |
387854 | Use-of-uninitialized-value in CPDF_RenderStatus::DrawShading | - | 2016-10-02 |
387853 | Use-of-uninitialized-value in FPDFAPI_inflate | - | 2016-10-02 |
387857 | Use-of-uninitialized-value in CPDF_SimpleParser::ParseWord | - | 2016-10-02 |
387850 | Use-of-uninitialized-value in FXSYS_atoi64 | - | 2016-10-02 |
387848 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
387847 | Use-of-uninitialized-value in opj_j2k_read_header_procedure | - | 2016-10-02 |
387846 | Use-of-uninitialized-value in _FaxGetRun | - | 2016-10-02 |
398235 | Security: possible another uninit memory with jpeg parsing | - | 2016-10-02 |
397834 | Use-of-uninitialized-value in CFX_WideString::InitStr | - | 2016-10-02 |
397835 | Use-of-uninitialized-value in chrome_pdf::PDFiumEngine::Paint | - | 2016-10-02 |
398109 | Security: Potential kernel privilege escalation when CONFIG_PPPOL2TP is enabled | - | 2016-10-02 |
397396 | Investigate lifetime of the NativeWindow parent in ExtensionUninstallDialog | - | 2016-10-02 |
398198 | Use-after-free in blink::WebSharedWorkerImpl::stopWorkerThread | $1,500 | 2016-10-02 |
397258 | Integer overflow from "offset + size" in extension.h and fpdfview.cpp | - | 2016-10-02 |
397549 | All of cc_unittests failing on yakju-clang-clankium | - | 2016-10-02 |
397656 | Heap-use-after-free in media::Pipeline::ErrorChangedTask | - | 2016-10-02 |
396961 | HTTP authentication dialog doesn't replace web contents when you type in to URL bar | - | 2016-10-02 |
396447 | Hooking up a remote audio track to local media stream would crash | - | 2016-10-02 |
396255 | Security: Uninitialized value possible in CJS_PublicMethods::MakeFormatDate | - | 2016-10-02 |
396054 | Security: Microphone access not blocked if you lock your phone. | $500 | 2016-10-02 |
397130 | HandleCloserAgent skips every other handle | - | 2016-10-02 |
395441 | Google Chrome not clearing the account data properly | - | 2016-10-02 |
395411 | ASSERTION FAILED: actualInfo->derefObjectFunction == wrapperTypeInfo.derefObjectFunction, UNKNOWN in blink::V8Event::createWrapper | $500 | 2016-10-02 |
395410 | Heap-use-after-free in syncer::SyncBackupManager::Init | $1,000 | 2016-10-02 |
395409 | Use-after-free in blink::MediaQueryList::stop | - | 2016-10-02 |
395679 | V8 executable page caps are dangerously high | - | 2016-10-02 |
395641 | UNKNOWN in SkImageFilter::Common::unflatten | - | 2016-10-02 |
395972 | Improper handling of calc parsing results in read access to pointer addresses | - | 2016-10-02 |
395461 | Use-after-free in CPDFSDK_PageView::LoadFXAnnots | - | 2016-10-02 |
395650 | SEGV in LocalWriteClosure::writeBlobToFileOnIOThread | - | 2016-10-02 |
395351 | Security: Chrome XSS Filter Bypassing | - | 2016-10-02 |
394902 | Use-after-free in several skia routines of memory freed by skia.dll!DWriteFontTypeface::`scalar deleting destructor' | - | 2016-10-02 |
395266 | Security: CJS_PublicMethods::StrRTrim() looks suspicious, may under/overflow | - | 2016-10-02 |
394026 | Heap-use-after-free in WebCore::Element::attrIfExists | - | 2016-10-02 |
393981 | Uninitialized IPC message in PopupBlockerTabHelper::ShowBlockedPopup | - | 2016-10-02 |
393833 | Use-of-uninitialized-value in content::webcrypto::platform::CreatePublicKeyAlgorithm | - | 2016-10-02 |
393831 | Use-of-uninitialized-value in CJS_PublicMethods::MakeRegularDate | - | 2016-10-02 |
393829 | Heap-use-after-free in blink::AXNodeObject::textUnderElement | - | 2016-10-02 |
394222 | Use-of-uninitialized-value in final_reordering_syllable | - | 2016-10-02 |
393938 | Uninitialized IPC message in PPB_Instance_Proxy::DeliverFrame | - | 2016-10-02 |
393605 | Heap-use-after-free in CPDF_Color::~CPDF_Color | - | 2016-10-02 |
393765 | Tracking bug for internal security fixes for Chrome 36, Release 0 | - | 2016-10-02 |
393595 | Use-after-free in WebCore::CustomElementMicrotaskRunQueue::dispatch | - | 2016-10-02 |
393572 | Padlock is shown after refresh despite displaying mixed content | - | 2016-10-02 |
393452 | UNKNOWN in memset | - | 2016-10-02 |
393603 | Use-of-uninitialized-value in CPDF_RenderStatus::GetStrokeArgb | - | 2016-10-02 |
393744 | Use-after-poison in WebCore::HeapPage<WebCore::FinalizedHeapObjectHeader>::markOrphaned | - | 2016-10-02 |
393602 | Heap-buffer-overflow in CCodec_FlateModule::FlateOrLZWDecode | - | 2016-10-02 |
393312 | Heap-use-after-free in WebCore::EventHandlerRegistry::documentDetached | - | 2016-10-02 |
393425 | Use-after-free in WebCore::FileReader::doAbort | - | 2016-10-02 |
393448 | Use-after-free in WebCore::CompositeEditCommand::replaceTextInNodePreservingMarkers | - | 2016-10-02 |
393221 | Heap-use-after-free in net::IOBuffer::data | - | 2016-10-02 |
393401 | Popups opened from a sandboxed iframe are not themselves sandboxed | $500 | 2016-10-02 |
392723 | Use-of-uninitialized-value in SkRect::setBoundsCheck | - | 2016-10-02 |
392598 | Use-after-free crash [@BrowserWindowCocoa::UpdateDevTools] | - | 2016-10-02 |
392719 | heap-use-after-free in CPDF_Color::~CPDF_Color | - | 2016-10-02 |
392510 | login_ChromeProfileSanitary indicates that Chrome is writing cookies to the Login profile | - | 2016-10-02 |
392720 | Use-of-uninitialized-value in CPDF_DocPageData::ReleaseColorSpace | - | 2016-10-02 |
392721 | Use-of-uninitialized-value in CXML_Parser::GetTagName | - | 2016-10-02 |
391929 | Potential integer overflow in fpdf_render_loadimage.cpp | - | 2016-10-02 |
392718 | Use-of-uninitialized-value in extensions::FrameNavigationState::SetNavigationCommitted | - | 2016-10-02 |
391905 | Use-of-uninitialized-value in icu_46::RegexMatcher::findUsingChunk | - | 2016-10-02 |
391910 | Use-of-uninitialized-value in WebCore::ErrorEventV8Internal::linenoAttributeGetterCallback | - | 2016-10-02 |
406562 | Vulnerability reported in net-misc/strongswan | - | 2016-10-02 |
406557 | Vulnerability reported in x11-libs/pixman | - | 2016-10-02 |
406142 | Heap-buffer-overflow in CFX_WideString::FromUTF16LE | - | 2016-10-02 |
405588 | Heap-buffer-overflow in CPDF_DeviceCS::GetRGB | - | 2016-10-02 |
406549 | Vulnerability reported in net-firewall/iptables | - | 2016-10-02 |
406548 | Vulnerability reported in dev-libs/libxml2 | - | 2016-10-02 |
406546 | Vulnerability reported in dev-libs/expat | - | 2016-10-02 |
406144 | Global-buffer-overflow in CFX_Font::LoadGlyphPath | - | 2016-10-02 |
404529 | Heap-use-after-free in blink::ImageQualityController::highQualityRepaintTimerFired | - | 2016-10-02 |
405416 | Stack-buffer-overflow in avpriv_aac_parse_header | - | 2016-10-02 |
404511 | Bad-cast to blink::IDBRequest from invalid vptrblink::GarbageCollectedFinalized<blink::IDBRequest>::finalizeGarbageCollectedObject;blink::HeapPage<blink::FinalizedHeapObjectHeader>::sweep;blink::ThreadHeap<blink::FinalizedHeapObjectHeader>::sweep | $3,500 | 2016-10-02 |
405421 | Heap-use-after-free in CPDF_IndexedCS::~CPDF_IndexedCS | - | 2016-10-02 |
405417 | Heap-use-after-free in SkOpSegment::addT | $1,000 | 2016-10-02 |
405335 | Heap-use-after-free in RemoteMediaPlayerManager::DidDownloadPoster | - | 2016-10-02 |
404513 | Heap-use-after-free in blink::FileReader::doAbort | - | 2016-10-02 |
403596 | Security: __lookupGetter__ and __lookupSetter__ can be used to leak all cross-origin data | - | 2016-10-02 |
403276 | Heap-use-after-free in blink::Document::didRemoveAllPendingStylesheet | $2,000 | 2016-10-02 |
403013 | use-after-free in mojo::internal::WeakServiceProvider::Clear | - | 2016-10-02 |
403665 | Heap-use-after-free in blink::TreeScopeAdopter::moveTreeToNewScope | - | 2016-10-02 |
404300 | Security: Blink inadequately whitelists child frames by name in access checks | - | 2016-10-02 |
404462 | Heap-use-after-free in blink::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
403409 | V8 Runtime_ArrayConcat uninitialized memory leak | $4,500 | 2016-10-02 |
402479 | Use-after-free in IDMap<blink::WebIDBCallbacks,1>::Releaser<1,0>::release_all | - | 2016-10-02 |
402407 | Heap-use-after-free in blink::RenderLayerScrollableArea::updateCompositingLayersAfterScroll | $3,000 | 2016-10-02 |
402297 | Heap-buffer-overflow in bracketAddOpening | - | 2016-10-02 |
402263 | Heap-use-after-free in blink::MediaQueryMatcher::viewportChanged | - | 2016-10-02 |
402260 | Heap-use-after-free in CPDF_Color::SetValue | $3,000 | 2016-10-02 |
402255 | Heap-use-after-free in blink::DocumentOrderedMap::add | - | 2016-10-02 |
402957 | Use-after-free in speech - saying "Hello" during the incognito window has closed | $2,000 | 2016-10-02 |
402702 | Security: Potential unsafe random number generation | - | 2016-10-02 |
402653 | Use-after-free from ASAN base::PlatformThreadRef::is_null() | - | 2016-10-02 |
401993 | Heap-use-after-free in unsigned long std::__1::__tree<std::__1::__value_type<unsigned int, std::__ | - | 2016-10-02 |
402240 | Heap-buffer-overflow in vp9_decode_frame | - | 2016-10-02 |
401463 | Bad-cast to blink::RenderBox from blink::RenderText;RenderBox.h:769:1 | $3,000 | 2016-10-02 |
401372 | Heap-use-after-free in CPDF_IndexedCS::~CPDF_IndexedCS | $3,000 | 2016-10-02 |
401364 | Heap-use-after-free in base::subtle::RefCountedThreadSafeBase::Release | - | 2016-10-02 |
401363 | Heap-use-after-free in blink::WebPagePopupImpl::closePopup | - | 2016-10-02 |
401362 | Heap-use-after-free in blink::RenderBox::pixelSnappedClientHeight | $2,000 | 2016-10-02 |
402218 | Bad-cast to blink::MediaQueryListListener from invalid vptr;ScriptedAnimationController.cpp:181:9 | - | 2016-10-02 |
401995 | Heap-buffer-overflow in CFX_ByteTextBuf::AppendChar | - | 2016-10-02 |
401580 | Heap-double-free in CFX_PathData::~CFX_PathData | - | 2016-10-02 |
400511 | Use-after-free in content::WebThreadBase::TaskObserverAdapter::WillProcessTask | - | 2016-10-02 |
400339 | Bad-cast to blink::ShadowRoot from blink::HTMLDocument;ShadowRoot.h:165:1 | - | 2016-10-02 |
400950 | Tracking bug for internal security fixes for Chrome 36, Release 1 | - | 2016-10-02 |
401115 | Security: UAF with Blob creation and Shared Workers | $1,500 | 2016-10-02 |
400996 | Heap-use-after-free in CPDF_TextStateData::~CPDF_TextStateData | $2,000 | 2016-10-02 |
400476 | Heap-use-after-free in blink::Event::path | $3,000 | 2016-10-02 |
399654 | UNKNOWN in v8::base::NoBarrier_Load | - | 2016-10-02 |
399495 | Heap-use-after-free in blink::WorkerSharedTimer::OnTimeout | $3,000 | 2016-10-02 |
399473 | Security: setpriority() is broadly allowed and allows to interact with other processes | - | 2016-10-02 |
399321 | Heap-use-after-free in blink::constructBidiRunsForLine | - | 2016-10-02 |
398925 | Security: SPDY connection sharing logic errors allows for MITM | $1,000 | 2016-10-02 |
399783 | Chrome_ChromeOS: Crash Report - blink::GraphicsLayer::setContentsOpaque | - | 2016-10-02 |
399768 | Security: NaCl inner sandbox escape on Windows due to mmap hole bug | - | 2016-10-02 |
399655 | Bad-cast to SessionService from invalid vptr;bind_internal.h:248:12 | $1,500 | 2016-10-02 |
398818 | Heap-use-after-free in blink::TreeScope::clearScopedStyleResolver | - | 2016-10-02 |
398438 | Heap-use-after-free in blink::Document::didRemoveAllPendingStylesheet | $2,000 | 2016-10-02 |
398384 | Security: Crash in memcpy in chrome_pdf::CopyImage | $3,000 | 2016-10-02 |
411165 | Use-of-uninitialized-value in std::__1::pair<std::__1::pair<WTF::StringImpl**, bool>, unsigned int> WTF:: | - | 2016-10-02 |
411160 | Use-of-uninitialized-value in cc::GLRenderer::EnqueueTextureQuad | - | 2016-10-02 |
411163 | Use-of-uninitialized-value in FXSYS_round | - | 2016-10-02 |
411162 | Use-of-uninitialized-value in webrtc::AudioDecoder::ConvertSpeechType | - | 2016-10-02 |
411161 | Use-of-uninitialized-value in CPDF_RenderStatus::GetFillArgb | - | 2016-10-02 |
411154 | Use-of-uninitialized-value in CPDF_DocPageData::ReleasePattern | - | 2016-10-02 |
411026 | Heap-use-after-free in blink::PersistentBase<blink::ThreadLocalPersistents< | - | 2016-10-02 |
410912 | UNKNOWN in v8::internal::MemoryChunk::IsFlagSet | - | 2016-10-02 |
410556 | UNKNOWN in v8::internal::JSFunction::context | $3,000 | 2016-10-02 |
410552 | Heap-buffer-overflow in SkOpSegment::findNextOp | $1,500 | 2016-10-02 |
410326 | Heap-use-after-free in CPDFSDK_PageView::LoadFXAnnots | - | 2016-10-02 |
411156 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
411159 | Use-of-uninitialized-value in content::MessageChannel::DrainEarlyMessageQueue | - | 2016-10-02 |
411133 | Bad-cast to cricket::WebRtcVoiceMediaChannel from webrtc::NetEqImpl;webrtcvideoengine.cc:1599:9 | - | 2016-10-02 |
409695 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
409692 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
409508 | Heap-use-after-free in blink::PODIntervalTree<int,blink::FloatingObject | - | 2016-10-02 |
409507 | Use-of-uninitialized-value in CFX_ByteString::~CFX_ByteString | - | 2016-10-02 |
410030 | CHECK failure in CHECK(!v8::internal::FLAG_enable_slow_asserts || (object->IsJSObject())) fa | - | 2016-10-02 |
409880 | Heap-use-after-free in cricket::WebRtcVoiceMediaChannel::SetupSharedBandwidthEstimation | - | 2016-10-02 |
409454 | Fetch event shouldn't fire for preflight requests | - | 2016-10-02 |
409506 | Heap-use-after-free in blink::AXNodeObject::document | - | 2016-10-02 |
409030 | After lock my Account login directly after clicking on google task manager | - | 2016-10-02 |
409023 | Heap-buffer-overflow in SkScalerContext_DW::generateImage | - | 2016-10-02 |
408739 | Heap-use-after-free in content::MessageChannel::DrainEarlyMessageQueue | - | 2016-10-02 |
409475 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | $3,000 | 2016-10-02 |
409373 | Heap-use-after-free in CPDF_Color::~CPDF_Color | $1,000 | 2016-10-02 |
408426 | Security: Page can run arbitrary code in the context of a UserGestureIndicator | - | 2016-10-02 |
408541 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | $3,000 | 2016-10-02 |
408154 | Heap-buffer-overflow in CPDF_DIBSource::DownSampleScanline | - | 2016-10-02 |
408164 | Heap-use-after-free in CPDF_ShadingObject::~CPDF_ShadingObject | $1,000 | 2016-10-02 |
408532 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | $1,000 | 2016-10-02 |
408160 | Bad-cast to blink::HTMLUnknownElement from blink::HTMLElement;ScriptWrappable.h:90:16 | - | 2016-10-02 |
407488 | Global-buffer-overflow in CFX_Font::LoadGlyphPath | $1,000 | 2016-10-02 |
407964 | Heap-buffer-overflow in opj_t2_read_packet_header | $1,000 | 2016-10-02 |
407341 | Stack-buffer-overflow in cf2_hintmap_build | - | 2016-10-02 |
407339 | Vulnerability reported in elfutils | - | 2016-10-02 |
407477 | Heap-use-after-free in blink::EventHandlerRegistry::documentDetached | - | 2016-10-02 |
408141 | Heap-buffer-overflow in CPDF_LabCS::TranslateImageLine | $3,000 | 2016-10-02 |
407614 | Heap-buffer-overflow in TIFF_PredictLine | - | 2016-10-02 |
407476 | Heap-buffer-overflow in CJPX_Decoder::Init | - | 2016-10-02 |
406879 | Heap-use-after-free in cc::LayerTreeHost::RecreateUIResources | - | 2016-10-02 |
406868 | Heap-use-after-free in CPDF_Object::Release | $1,500 | 2016-10-02 |
406850 | Bad-cast to blink::AudioSummingJunction from invalid vptr;AudioContext.cpp:787:9 | - | 2016-10-02 |
406806 | Heap-buffer-overflow in CPDF_ICCBasedCS::GetRGB | - | 2016-10-02 |
406600 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | $500 | 2016-10-02 |
406895 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
406908 | Heap-buffer-overflow in CPDF_DIBSource::TranslateScanline24bpp | $1,000 | 2016-10-02 |
407235 | libcurl: Wildcard IP in cert's CN field can allow server spoof | - | 2016-10-02 |
406871 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in blink::InlineTextBox::constructTextRun | - | 2016-10-02 |
406591 | Heap-buffer-overflow in CPDF_SyntaxParser::SearchWord | $500 | 2016-10-02 |
406593 | Draw the image outside of the inline frame | $1,500 | 2016-10-02 |
415689 | Add an HSTS and key pin preload rule for chrome.com | - | 2016-10-02 |
415866 | Use-of-uninitialized-value in SkOpSegment::addTCoincident | $2,000 | 2016-10-02 |
415305 | UNKNOWN in blink::HRTFDatabaseLoader::load | - | 2016-10-02 |
415256 | SSLBlockingPage option mask isn't ORed | - | 2016-10-02 |
415012 | Heap-use-after-free in content::BrowserPlugin::~BrowserPlugin | - | 2016-10-02 |
415307 | Heap-buffer-overflow in chrome_pdf::PDFiumEngine::GetPageRect | $1,500 | 2016-10-02 |
415407 | ASSERTION FAILED: curr->isRenderInline(), UNKNOWN in blink::RenderInline::splitInlines | - | 2016-10-02 |
415306 | Heap-use-after-free in scoped_refptr<base::MessageLoopProxy>::operator= | - | 2016-10-02 |
414504 | Heap-use-after-free in opj_t1_decode_cblks | $1,000 | 2016-10-02 |
414310 | Heap-buffer-overflow in opj_jp2_apply_cdef | $1,000 | 2016-10-02 |
414182 | Heap-buffer-overflow in opj_t2_read_packet_header | - | 2016-10-02 |
414134 | Use-of-uninitialized-value in cricket::WebRtcVoiceMediaChannel::SetupSharedBweOnChannel | - | 2016-10-02 |
414606 | Heap-buffer-overflow in opj_v4dwt_interleave_h | $3,000 | 2016-10-02 |
414661 | Security: heap-use-after-free in CPDF_ShadingPattern::Clear() | - | 2016-10-02 |
414525 | Heap-buffer-overflow in opj_dwt_decode | $3,000 | 2016-10-02 |
414109 | Use-of-uninitialized-value in unsigned int blink::WidthIterator::advanceInternal<blink::SurrogatePairAwareTextIterator> | $1,000 | 2016-10-02 |
414100 | ASSERTION FAILED: node->isMediaControlElement(), UNKNOWN in blink::mediaControlElementType | - | 2016-10-02 |
414089 | Heap-double-free in j2k_read_ppm_v3 | $3,000 | 2016-10-02 |
414046 | Heap-use-after-free in CPDF_ImageObject::~CPDF_ImageObject | $2,000 | 2016-10-02 |
414036 | UNKNOWN in libc.so.6 | $2,000 | 2016-10-02 |
414124 | Security: TLS handshake and certificate signature forgery is possible using BleichenbacherĂąÂÂs Low-Exponent Attack due to faulty ASN.1 length decoding | $5,000 | 2016-10-02 |
414118 | Heap-use-after-free in content::ServiceWorkerControlleeRequestHandler::DidLookupRegistrationForMai | - | 2016-10-02 |
413850 | Use-of-uninitialized-value in chrome_pdf::PDFiumEngine::OnMouseMove | - | 2016-10-02 |
414026 | Do Not Cache Resources Retrieved Via Broken HTTPS in AppCache Or Service Worker | $500 | 2016-10-02 |
413744 | Heap-use-after-free in JavaObjectWeakGlobalRef::Assign | - | 2016-10-02 |
413743 | Heap-use-after-free in void cc::PreCalculateMetaInformation<cc::LayerImpl> | - | 2016-10-02 |
413706 | Security: Hotspot+appcache allows permanent sslstrip attack | - | 2016-10-02 |
413534 | Bad-cast to blink::AXMenuList from blink::AXList;AXMenuList.h:58:1 | - | 2016-10-02 |
413884 | Security: bug in nvmap Nvidia driver allows for privilege escalation. | - | 2016-10-02 |
413831 | Security: Issue with facetime:// and facetime-audio:// schemes | - | 2016-10-02 |
413375 | Negative-size-param in opj_t2_decode_packets | $1,000 | 2016-10-02 |
413316 | Use-after-free in blink::LocalDOMWindow::willDetachDocumentFromFrame | - | 2016-10-02 |
413094 | Security: ServiceWorker onfetch should not intercept Flash files or crossdomain.xml | - | 2016-10-02 |
413041 | Use-after-free in blink::ScriptWrappable::wrap | - | 2016-10-02 |
412790 | Use-of-uninitialized-value in FindSortableTop | - | 2016-10-02 |
413530 | Heap-use-after-free in blink::FrameView::scheduleRelayout | - | 2016-10-02 |
413447 | Heap-double-free in opj_tcd_code_block_dec_deallocate | - | 2016-10-02 |
413232 | Use-of-uninitialized-value in v8::internal::JSObject::UpdateAllocationSite | - | 2016-10-02 |
412457 | Heap-buffer-overflow in tt_face_get_location | - | 2016-10-02 |
411323 | Heap-use-after-free in content::RenderFrameImpl::Send | - | 2016-10-02 |
411320 | Heap-use-after-free in media::TimeDeltaInterpolator::GetInterpolatedTime | - | 2016-10-02 |
411318 | Heap-use-after-free in content::BufferedDataSource::ReadCallback | - | 2016-10-02 |
411735 | Use-after-free in blink::V8SVGFEMergeNodeElement::refObject | - | 2016-10-02 |
411329 | Use-of-uninitialized-value in SkColorTypeValidateAlphaType | - | 2016-10-02 |
411177 | Use-of-uninitialized-value in chrome_pdf::PageIndicator::OnTimerFired | - | 2016-10-02 |
411167 | Use-of-uninitialized-value in WebCore::RenderTableSection::dirtiedRows | - | 2016-10-02 |
411213 | Possible out of bounds access in BreakIterator class | - | 2016-10-02 |
411210 | CHECK failure in CHECK(start <= end) failed: ../../v8/src/heap/spaces.cc(1722) | - | 2016-10-02 |
422621 | Security: Cloud Print Connect XMPP connection leaks auth token to active network attacker | - | 2016-10-02 |
422492 | Heap-buffer-overflow in SkOpSegment::blindCoincident | $1,000 | 2016-10-02 |
421981 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-02 |
421817 | Security: handleAuthenticatorUrl to launch any activity from web page | $2,000 | 2016-10-02 |
421720 | Crash in RenderBlock::willBeDestroyed when removing from a map and destroying a continuation that has been already destroyed | - | 2016-10-02 |
422482 | Use-of-uninitialized-value in AvatarMenuBubbleView::LinkClicked | - | 2016-10-02 |
422374 | Google Account Sync auth token leaked to active network attacker who suppresses XMPP STARTTLS | - | 2016-10-02 |
421500 | Use-of-uninitialized-value in extensions::NativeMessageProcessHost::OnHostProcessLaunched | - | 2016-10-02 |
421332 | Security: Completely spoofable origin, including lock sign | $1,000 | 2016-10-02 |
421504 | Heap-use-after-free in blink::XMLHttpRequest::handleRequestError | - | 2016-10-02 |
421321 | Security: Use-after-free in blink::PageAnimator::serviceScriptedAnimations | - | 2016-10-02 |
421196 | Security: intra-object-overflow in third_party/pdfium/core/src/fpdfapi/fpdf_cmaps/fpdf_cmaps.cpp | - | 2016-10-02 |
421499 | Use-of-uninitialized-value in ucase_toupper_52 | - | 2016-10-02 |
421691 | Security: Accelerometer/gyroscope leak keystrokes and speech | - | 2016-10-02 |
421090 | Security: NaCl sandbox escape via DRAM "rowhammer" memory corruption | - | 2016-10-02 |
420450 | Heap-use-after-free in blink::RenderBlock::willBeDestroyed | - | 2016-10-02 |
421130 | Heap-use-after-free in blink::Element::setAttribute | - | 2016-10-02 |
421132 | Stack-buffer-underflow in SkDPoint::approximatelyEqual | $1,500 | 2016-10-02 |
419542 | Potential UAF in SSLErrorClassification during shutdown in tests | - | 2016-10-02 |
419774 | Heap-use-after-free in blink::HarfBuzzShaper::setGlyphPositionsForHarfBuzzRun | - | 2016-10-02 |
419428 | Uninit in featureWithPositiveInteger | - | 2016-10-02 |
419383 | Security: SOP Bypass of Data Exfiltration with CSS | $1,337 | 2016-10-02 |
419265 | ASSERTION FAILED: fontPlatformData, Heap-use-after-free in base::MessageLoop::PostTask | - | 2016-10-02 |
419060 | Heap-use-after-free in vorbis_decode_frame | $1,500 | 2016-10-02 |
419036 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
418976 | Heap-buffer-overflow in opj_tcd_get_decoded_tile_size | $500 | 2016-10-02 |
418881 | Heap-buffer-overflow in color_sycc_to_rgb | $1,000 | 2016-10-02 |
418585 | Heap-buffer-overflow in cff_get_glyph_name | - | 2016-10-02 |
419320 | Heap-use-after-free in CPDF_GeneralStateData::~CPDF_GeneralStateData | - | 2016-10-02 |
418402 | Security: Cross-Page and Cross-Domain Propagation of Click events on Mobile Devices | $1,000 | 2016-10-02 |
418381 | Heap-buffer-overflow in SkOpSegment::addCoinOutsides | $1,500 | 2016-10-02 |
418114 | Use-after-free in base::MessageLoop::DeleteSoonInternal | - | 2016-10-02 |
417841 | Mixed content resources (e.g. scripts) can be loaded using redirection | $1,000 | 2016-10-02 |
418582 | Heap-buffer-overflow in tt_cmap6_char_index | - | 2016-10-02 |
418161 | Heap-buffer-overflow in void SkMatrixConvolutionImageFilter::filterPixels<ClampPixelFetcher, false> | $2,000 | 2016-10-02 |
417210 | ThreadSanitizer v2 reports a heap-use-after-free in _get_bitmap_surface | - | 2016-10-02 |
417731 | Heap-use-after-free in blink::BaseMultipleFieldsDateAndTimeInputType::pickerIndicatorChooseValue | - | 2016-10-02 |
416526 | V8 slow/fast properties confusion | - | 2016-10-02 |
416696 | Container-overflow in chrome_pdf::PDFiumEngine::SelectFindResult | - | 2016-10-02 |
417329 | Security: code execution via bash environment variables | - | 2016-10-02 |
416528 | Out-of-bounds write in the browser via P2PHostMsg_Send IPC | - | 2016-10-02 |
416319 | Heap-use-after-free in CPDF_Color::~CPDF_Color | - | 2016-10-02 |
416323 | UNKNOWN in TcmapEncodingTable::GetSubtableAtIndex | $1,000 | 2016-10-02 |
416449 | Chrome exploit: V8 properties + P2PHostMsg_Send | $27,634 | 2016-10-02 |
416289 | Heap-buffer-overflow in GrBufferAllocPool::putBack | - | 2016-10-02 |
416362 | Potential UAF at WebCore::TimerBase::setNextFireTime | $2,000 | 2016-10-02 |
426890 | A vulnerability in run-mailcap can lead to code execution on Debian-based Linux distros with certain (nonstandard) desktop environments | $500 | 2016-10-02 |
426762 | Use-of-uninitialized-value in blink::Font::glyphDataAndPageForCharacter | $1,000 | 2016-10-02 |
426760 | Bad-cast to blink::ScriptWrappable from invalid vptr;ScriptWrappable.h:202:9 | - | 2016-10-02 |
426758 | Heap-use-after-free in blink::ScriptStreamer::notifyFinished | - | 2016-10-02 |
426757 | Use-after-free in blink::RenderSVGResourcePattern::patternForRenderer | - | 2016-10-02 |
425280 | Security: Flash Cross Domain Policy Bypass by Using File Upload and Redirection - only in Chrome | $2,000 | 2016-10-02 |
425263 | Security: wpa_supplicant CVE-2014-3686 | - | 2016-10-02 |
425153 | Heap-buffer-overflow in j2k_read_ppm_v3 | - | 2016-10-02 |
425152 | Heap-buffer-overflow in opj_stream_read_data | - | 2016-10-02 |
425151 | Heap-buffer-overflow in opj_tcd_init_decode_tile | - | 2016-10-02 |
425150 | Heap-use-after-free in opj_t1_decode_cblks | - | 2016-10-02 |
425040 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | - | 2016-10-02 |
425980 | UNKNOWN in media::container_names::DetermineContainer | $500 | 2016-10-02 |
425856 | Global-buffer-overflow in SkStrSearch | - | 2016-10-02 |
425585 | Use-of-uninitialized-value in v8::internal::Decoder<v8::internal::Simulator>::DecodeBranchSystemException | $2,500 | 2016-10-02 |
424998 | Heap-use-after-free in SkTypefaceCache::FindByProcAndRef | - | 2016-10-02 |
425001 | ASSERTION FAILED: repetitions > 0, UNKNOWN in blink::CSSPropertyParser::parseGridTrackRepeatFunction | - | 2016-10-02 |
424961 | Security: Local file access in plugins via chrome-extension protocol handler vulnerability | - | 2016-10-02 |
424957 | Use-of-uninitialized-value in blink::TransformationMatrix::rotate3d | - | 2016-10-02 |
424956 | Bad-cast to blink::RenderText from blink::RenderImage;RenderText.h:230:1 | - | 2016-10-02 |
425006 | Heap-use-after-free in blink::WebGLRenderingContextBase::printGLErrorToConsole | - | 2016-10-02 |
424999 | Use-of-uninitialized-value in aura::Window::GetNativeWindowProperty | - | 2016-10-02 |
424981 | Security: Flash Camera.copyToByteArray() memory corruption | - | 2016-10-02 |
424331 | UNKNOWN in opj_read_bytes_LE | $1,000 | 2016-10-02 |
424215 | Heap-buffer-overflow in WebRtcIsacfix_Decode | - | 2016-10-02 |
423899 | Security: UAF in CFX_DIBSource::GetWidth() | - | 2016-10-02 |
423891 | Bad-cast to blink::PODRedBlackTree<blink::PODInterval<int, blink::FloatingObject *> >::Node from invalid vptr;PODIntervalTree.h:175:33 | - | 2016-10-02 |
423703 | Security: Race condition in Flash workers may cause an exploitable double free | $7,500 | 2016-10-02 |
424619 | Reading from index -Infinity on typed array may cause random memory corruption (?) | - | 2016-10-02 |
424914 | ASSERTION FAILED: !current.value()->isInheritedValue(), Heap-use-after-free in blink::Element::detach | - | 2016-10-02 |
424216 | Heap-use-after-free in content::GpuChannelHost::Send | - | 2016-10-02 |
422765 | Heap-use-after-free in net::ClientCertStoreNSS::GetClientCertsOnWorkerThread | - | 2016-10-02 |
422693 | UNKNOWN in SuperBlitter::blitH | $2,000 | 2016-10-02 |
423084 | Chrome on iOS does not block active mixed content (scripts) | - | 2016-10-02 |
422824 | Heap-buffer-overflow in icu_52::RegexMatcher::MatchChunkAt | $4,000 | 2016-10-02 |
429779 | Heap-use-after-free in SetVolume | - | 2016-10-02 |
429922 | Security: A compromised renderer process could dismiss interstitial warnings it triggers | - | 2016-10-02 |
429740 | Heap-use-after-free in content::RTCPeerConnectionHandler::Observer::OnIceCandidate | - | 2016-10-02 |
429838 | Security: OpenSearch description files can be loaded from file:// URLs | $500 | 2016-10-02 |
429778 | UNKNOWN in webrtc::SdpSerialize | - | 2016-10-02 |
429626 | heap-buffer-overflow (read of size 1) at an unpronounceable function below SkScalerContext_FreeType_Base::generateGlyphImage | - | 2016-10-02 |
429679 | Heap-use-after-free in BookmarkContextMenuController::IsCommandIdEnabled | - | 2016-10-02 |
429585 | Heap-use-after-free in GetStats | - | 2016-10-02 |
429666 | Heap-use-after-free in blink::Node::setNeedsStyleRecalc | $2,000 | 2016-10-02 |
429542 | Security: file-to-file SOP bypass on Linux via /proc/self/fd/ | - | 2016-10-02 |
429276 | Security: Use after free in Flash (StageVideoAvailabilityEvent) can make bad things happen | $7,500 | 2016-10-02 |
429379 | Use-of-uninitialized-value in SkPath::arcTo | - | 2016-10-02 |
429201 | Heap-use-after-free in cc::PictureLayerTiling::UpdateEvictionCacheIfNeeded | - | 2016-10-02 |
429194 | Use-of-uninitialized-value in v8::internal::HOptimizedGraphBuilder::BuildBinaryOperation | - | 2016-10-02 |
429166 | Security: Heap Memory Corruption off-by-one (Overwrite 0x2C with 0x00) in ffmpeg function matroska_fix_ass_packet | - | 2016-10-02 |
429477 | Heap-use-after-free in TrackOnSuccess | - | 2016-10-02 |
429478 | Heap-use-after-free in blink::WebGLRenderingContextBase::printGLErrorToConsole | - | 2016-10-02 |
429244 | CSP Bypass on M39 | - | 2016-10-02 |
428829 | Heap-use-after-free in subtle::PrefMemberBase::VerifyPref | - | 2016-10-02 |
428828 | Heap-use-after-free in content::IndexedDBDatabase::RunVersionChangeTransaction | - | 2016-10-02 |
428800 | Heap-buffer-overflow in epoll_add | - | 2016-10-02 |
428789 | Heap-use-after-free in SkXfermodeImageFilter::~SkXfermodeImageFilter | - | 2016-10-02 |
428578 | Multiple Windows Kernel Crashes in Font Parsing | $6,500 | 2016-10-02 |
428561 | Heap-use-after-free in base::SupportsUserData::GetUserData | $1,500 | 2016-10-02 |
429139 | Heap-buffer-overflow in opj_t1_decode_cblks | - | 2016-10-02 |
429134 | Heap-buffer-overflow in CPDF_LabCS::GetDefaultValue | - | 2016-10-02 |
428557 | Stack-buffer-overflow in _XData32 | $2,000 | 2016-10-02 |
427397 | Heap-buffer-overflow in blink::CSPSourceList::parseHash | - | 2016-10-02 |
427272 | Security: UaF in FileSelectHelper::FileSelectedWithExtraInfo | $1,000 | 2016-10-02 |
427266 | Heap-use-after-free in matroska_read_seek | $2,000 | 2016-10-02 |
427249 | ASSERTION FAILED: m_pendingStylesheets > 0, Heap-use-after-free in blink::StyleEngine::clearResolver | $2,000 | 2016-10-02 |
427196 | console.log is breaking chrome://extensions | - | 2016-10-02 |
428137 | Heap-buffer-overflow in void v8::internal::String::WriteToFlat<unsigned short> | - | 2016-10-02 |
427303 | UNKNOWN in blink::HRTFDatabaseLoader::load | - | 2016-10-02 |
427108 | Heap-use-after-free in blink::PendingScript::stopWatchingForLoad | $2,000 | 2016-10-02 |
436022 | Security: Race condition in workers may cause an exploitable double free by abusing bytearray.compress() | $7,500 | 2016-10-02 |
435825 | UNKNOWN in v8::internal::String::length | - | 2016-10-02 |
435815 | Bad-cast to blink::RenderTable from blink::RenderBlockFlow;RenderTable.h:366:1 | - | 2016-10-02 |
435567 | Use-of-uninitialized-value in void v8::internal::ScavengingVisitor< | - | 2016-10-02 |
435514 | Heap-use-after-free in rdft_calc_c | - | 2016-10-02 |
435383 | Heap-based buffer overflow in Flash PCRE regex engine | $3,000 | 2016-10-02 |
435073 | CHECK failure in CHECK(p->IsSmi()) failed: ../../v8/src/objects-debug.cc(32) | $3,500 | 2016-10-02 |
435880 | Heap-buffer-overflow in std::less<std::string>::operator | $4,500 | 2016-10-02 |
434970 | Heap-use-after-free in blink::ScopedStyleResolver::collectFeaturesTo | - | 2016-10-02 |
434964 | Chrome's uninstaller launches IE w/ an unquoted path to iexplore.exe | - | 2016-10-02 |
434733 | Use-after-free in blink::ResourceFetcher::didFinishLoading | - | 2016-10-02 |
434732 | ASSERTION FAILED: !m_deletionHasBegun, UNKNOWN in blink::Node::remove | - | 2016-10-02 |
434972 | Heap-use-after-free in webrtc::internal::SynchronousMethodCall::Invoke | - | 2016-10-02 |
434723 | Heap-use-after-free in content::MediaStreamTrackMetricsObserver::SendLifetimeMessages | - | 2016-10-02 |
434569 | Security: Heap-use-after-free in SupportsUserData::GetUserData | $500 | 2016-10-02 |
434728 | Use-after-free in blink::RenderLayer::updatePagination | - | 2016-10-02 |
434499 | Security: Hera color from previous page remains on interstitial load | - | 2016-10-02 |
433866 | Use-of-uninitialized-value in getNextNormalizedChar | $1,000 | 2016-10-02 |
433860 | Use-after-free in blink::AXObject::document | - | 2016-10-02 |
434136 | WebAudio render that coincides with GC graph mutation can cause snap | $4,000 | 2016-10-02 |
433359 | UNKNOWN in void SkMatrixConvolutionImageFilter::filterPixels<UncheckedPixelFetcher, fa | - | 2016-10-02 |
433357 | Use-after-free in blink::HTMLPlugInElement::renderPartForJSBindings | - | 2016-10-02 |
433078 | Security: OOB read in dhcpcd | - | 2016-10-02 |
433445 | UNKNOWN in v8::internal::FixedArray::get | $1,500 | 2016-10-02 |
433170 | Media permission not displayed in PageInfo | - | 2016-10-02 |
432209 | Heap-buffer-overflow in icu_52::RegexMatcher::MatchChunkAt | - | 2016-10-02 |
432575 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in blink::InlineTextBox::constructTextRun | - | 2016-10-02 |
432572 | Heap-use-after-free in std::unordered_map<int,enum gfx::GpuMemoryBufferType,std::hash<int>,std::eq | - | 2016-10-02 |
431504 | Security: Cookie injection by Proxy with 407 response | $500 | 2016-10-02 |
431288 | Heap-buffer-overflow in opj_tcd_init_decode_tile | $500 | 2016-10-02 |
431860 | Heap-use-after-free in v8::internal::Isolate::counters | - | 2016-10-02 |
431602 | UNKNOWN in v8::internal::RootMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
431603 | ASSERTION FAILED: to <= m_run.length(), UNKNOWN in blink::HarfBuzzShaper::setDrawRange | - | 2016-10-02 |
430787 | UNKNOWN in v8::internal::HeapObjectIterator::FromCurrentPage | - | 2016-10-02 |
430786 | Heap-use-after-free in webrtc::PeerConnection::OnAddDataChannel | - | 2016-10-02 |
430630 | Security: Content settings (e.g. disallow images/javascript) not honored on frames created while interstitial is showing | - | 2016-10-02 |
430925 | Heap-use-after-free in webrtc::PeerConnection::OnSessionStateChange | - | 2016-10-02 |
430928 | Heap-use-after-free in webrtc::RemoteAudioSource::SetVolume | - | 2016-10-02 |
430891 | Heap-buffer-overflow in opj_j2k_tcp_destroy | $2,000 | 2016-10-02 |
430533 | Heap-use-after-free in cc::ResourceProvider::ScopedWriteLockGpuMemoryBuffer::GetGpuMemoryBuffer | - | 2016-10-02 |
430353 | UNKNOWN in icu_52::RegexMatcher::MatchChunkAt | $5,000 | 2016-10-02 |
430351 | Heap-buffer-overflow in blink::CSPSourceList::parseNonce | - | 2016-10-02 |
430588 | Security: backport seccomp-tsync | - | 2016-10-02 |
430566 | Heap-buffer-overflow in opj_jp2_apply_pclr | $500 | 2016-10-02 |
442710 | Stack-buffer-overflow in v8::internal::MarkCompactCollector::SweepInParallel | $3,000 | 2016-10-02 |
442756 | Security: Denial of service attack against third-parties using web sockets | - | 2016-10-02 |
442585 | Security: Flash Player RegExp Object Integer Signedness Error | $4,000 | 2016-10-02 |
442454 | Use-after-free in blink::RenderLayer::invalidatePaintForBlockSelectionGaps | - | 2016-10-02 |
442806 | Heap-use-after-free in blink::TreeScopeEventContext::ensureEventPath | $3,000 | 2016-10-02 |
442670 | Security: NPAPI windowless flash can listen system input events (bypassing browser) | - | 2016-10-02 |
441834 | Chromoting host must call CloseClipboard() with anonymous access token | - | 2016-10-02 |
442121 | ASSERTION FAILED: !value || (value->isValueList()) | $2,000 | 2016-10-02 |
440694 | Security: Windows Token Hardening - Ensure Opening of Named Pipes Specifies Anonymous Impersonation Level | - | 2016-10-02 |
440834 | Use-after-free in blink::HTMLImageFallbackHelper::createAltTextShadowTree | - | 2016-10-02 |
440833 | Heap-buffer-underflow in blink::AXRenderObject::computeAccessibilityIsIgnored | - | 2016-10-02 |
440990 | Security: module locking can be disable after boot in verified mode | - | 2016-10-02 |
440693 | Security: Windows Token Hardening - Impersonate Anonymous Token Across CloseClipboard Calls | - | 2016-10-02 |
440692 | Security: Windows Token Hardening - Modify Broker Process Token IL Policy | - | 2016-10-02 |
440572 | Security: Circumvent Safe Browsing with data urls | - | 2016-10-02 |
441095 | Heap-use-after-free in blink::ResourceResponse::~ResourceResponse | - | 2016-10-02 |
440836 | Bad-cast to blink::Element from blink::CDATASection;Element.h:651:1 | - | 2016-10-02 |
440268 | Security: Encoded script URL can get around the path restriction | - | 2016-10-02 |
439992 | Use-of-uninitialized-value in icu_52::RegexMatcher::findUsingChunk | - | 2016-10-02 |
439877 | Security: HTML Imports ignores Content-Type and Content-Disposition headers. | - | 2016-10-02 |
440435 | Heap-use-after-free in base::MessageLoop::PostTask | - | 2016-10-02 |
439319 | Use-after-free in blink::TreeScope::comparePosition | - | 2016-10-02 |
438638 | Use-after-free in blink::AXSpinButton::elementRect | - | 2016-10-02 |
438364 | Heap-use-after-free in blink::VectorMath::vadd | - | 2016-10-02 |
438363 | UNKNOWN in avio_read | - | 2016-10-02 |
438157 | Windows Sandbox: Chromium's FILES_ALLOW_READONLY policy can be bypassed to create empty files or delete the contents of existing files | - | 2016-10-02 |
437960 | chrome.identity.getAuthToken leaks master-token and gives attacker a full control over a two-factor-protected Google account | - | 2016-10-02 |
438365 | Heap-use-after-free in views::X11WholeScreenMoveLoop::RunMoveLoop | - | 2016-10-02 |
437681 | ASSERTION FAILED: !result, Heap-use-after-free in blink::DirectConvolver::process | - | 2016-10-02 |
437655 | Heap-use-after-free in vp9_setup_mask | - | 2016-10-02 |
437636 | Bad-cast to blink::AudioNode from invalid vptr;AudioNode.cpp:401:13 | - | 2016-10-02 |
437472 | Heap-buffer-overflow in android::BlobCache::flatten | - | 2016-10-02 |
437464 | Use-of-uninitialized-value in udev_monitor_enable_receiving | - | 2016-10-02 |
437682 | Heap-use-after-free in blink::AudioChannel::zero | - | 2016-10-02 |
437651 | Heap-use-after-free in void blink::ImageDecodingStore::insertCacheInternal<blink::ImageDecodingSto | $3,000 | 2016-10-02 |
437399 | Heap-buffer-overflow in blink::BidiResolver<blink::InlineIterator, blink::BidiRun>::applyL1Rule | $500 | 2016-10-02 |
436520 | Heap-buffer-overflow in content::RtcDataChannelHandler::OnStateChange | - | 2016-10-02 |
437458 | Heap-buffer-overflow in blink::Character::expansionOpportunityCount | - | 2016-10-02 |
437441 | Security: Use After Free in Flash MessageChannel.send() | $5,000 | 2016-10-02 |
447773 | ASSERTION FAILED: !node || isElementOfType<const T>(*node) | - | 2016-10-02 |
447644 | Use-of-uninitialized-value in blink::DocumentAnimations::updateAnimationTimingIfNeeded | - | 2016-10-02 |
447567 | UNKNOWN in v8::internal::JSFunction::shared | - | 2016-10-02 |
446672 | UNKNOWN in libc.so.6 | - | 2016-10-02 |
446538 | File download .dotfiles sanitization fails when the file starts with a space | - | 2016-10-02 |
446537 | Add "Show hidden files" to gear menu | - | 2016-10-02 |
447664 | ASSERTION FAILED: !value || (value->isPrimitiveValue()) | - | 2016-10-02 |
446164 | Security: Integer Overflow in WebGL | $3,000 | 2016-10-02 |
446078 | Persistent DoS attack on storage space on Chrome OS | - | 2016-10-02 |
446076 | ASSERTION FAILED: !m_deletionHasBegun | - | 2016-10-02 |
446037 | Use-after-free in blink::RenderQuote::attachQuote | - | 2016-10-02 |
446033 | UNKNOWN in Read_CVT | $1,000 | 2016-10-02 |
446032 | Security: OOM situation can result in heap buffer overflow in CFX_BinaryBuf (pdfium) | $3,000 | 2016-10-02 |
446459 | Security: Proxy credential leak: WebSockets send proxy headers to destination server | - | 2016-10-02 |
445831 | UNKNOWN in SA8_alpha_D32_nofilter_DX | - | 2016-10-02 |
445808 | Stack-buffer-overflow in SkPackBits::Unpack8 | $2,000 | 2016-10-02 |
445809 | Heap-buffer-overflow in SkBitmap::ReadRawPixels | $5,000 | 2016-10-02 |
445902 | Use-of-uninitialized-value in GrBitmapTextGeoProc::getGLProcessorKey | - | 2016-10-02 |
445807 | Global-buffer-overflow in SkGradientShaderBase::SkGradientShaderBase | $5,000 | 2016-10-02 |
445810 | Heap-buffer-overflow in SkImageFilter::Common::unflatten | $5,000 | 2016-10-02 |
445741 | Heap-use-after-free in base::MessageLoop::DeleteSoonInternal | - | 2016-10-02 |
445747 | Use-after-free in std::_Tree<std::_Tmap_traits<base::FilePath,bool,std::less<base::FilePath>, | - | 2016-10-02 |
445653 | Security: Potential bugs/vulnerabilities in GPU code | - | 2016-10-02 |
445638 | ASSERT_NOT_REACHED in blink::LengthStyleInterpolation::interpolableValueToLength | - | 2016-10-02 |
445332 | ASSERTION FAILED: !value || (value->isPrimitiveValue()) | $1,500 | 2016-10-02 |
445305 | Use-of-uninitialized-value in blink::MediaControls::shouldHideMediaControls | - | 2016-10-02 |
445304 | ASSERTION FAILED: obj->isRenderInline() || obj == this | - | 2016-10-02 |
445679 | Memory error when importing bogus EC private key from PKCS8 into BoringSSL | - | 2016-10-02 |
445303 | Heap-buffer-overflow in void blink::SearchBuffer::append<unsigned char> | - | 2016-10-02 |
445285 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | $2,000 | 2016-10-02 |
445267 | UNKNOWN in v8::internal::Invoke | $3,500 | 2016-10-02 |
445107 | Use of unitialized value in toDataUrl / jpeg encoding path | - | 2016-10-02 |
444957 | Heap-use-after-free in OpenPDFInReaderBubbleView::ButtonPressed | $500 | 2016-10-02 |
444927 | Security: Inherited designMode and cross-window drag-n-drop allow to modify a cross-origin iframe's DOM | $3,000 | 2016-10-02 |
444717 | Invalid RenderFrameHost pointer is passed to WebNavigationTabObserver::DidOpenRequestedURL in test WebNavigationApiTest.CrossProcess | - | 2016-10-02 |
444707 | Use-of-uninitialized-value in unsigned int blink::SimpleShaper::advanceInternal<blink::SurrogatePairAware | $1,000 | 2016-10-02 |
444695 | UNKNOWN in v8::internal::Invoke | $3,500 | 2016-10-02 |
444681 | Use-after-poison in v8::internal::compiler::InstructionSelector::InitializeCallBuffer | $3,500 | 2016-10-02 |
444573 | Use-of-uninitialized-value in ucnv_io_getConverterName_52 | $1,000 | 2016-10-02 |
444546 | Heap/Stack Memory Info Leak - FFMPEG libavformat\mov.c | $2,000 | 2016-10-02 |
444539 | Heap Corruption - FFMPEG libavformat\mov.c - Use-After-Free/Double Free | $4,000 | 2016-10-02 |
444198 | Security: ViewHostMsg_RunFileChooser IPC allows renderer control over absolute path | - | 2016-10-02 |
444084 | UNKNOWN in v8::internal::IC::raw_target | - | 2016-10-02 |
443744 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
443675 | Heap-use-after-free in blink::TreeScope::clearScopedStyleResolver | - | 2016-10-02 |
444522 | Heap-buffer-overflow in ff_mov_read_stsd_entries | $5,000 | 2016-10-02 |
443356 | Security: No process swap between file:// and data: URLs | - | 2016-10-02 |
443333 | Security: tracking bug for ffmpeg H.264 fixes | - | 2016-10-02 |
443115 | Heap-use-after-free in blink::PendingScript::stopWatchingForLoad | $2,000 | 2016-10-02 |
443017 | Heap-use-after-free in blink::ScopedStyleResolver::collectFeaturesTo | $3,000 | 2016-10-02 |
443476 | Use-after-free in WTF::VectorDestructor<1,blink::Canvas2DLayerBridge::MailboxInfo>::destruct | - | 2016-10-02 |
443274 | memory access bug in harfbuzz when a carefully crafted font is fed | - | 2016-10-02 |
451918 | ASSERTION FAILED: it != m_customElementBindings.end() | - | 2016-10-02 |
451773 | ASSERTION FAILED: !object || (object->isTableCell()) | - | 2016-10-02 |
451753 | UNKNOWN in DestroyPropertySheetPage+0x4e | - | 2016-10-02 |
451685 | Use-after-poison in blink::callTransactionErrorCallback | - | 2016-10-02 |
451684 | ASSERTION FAILED: node->isMediaControlElement() | - | 2016-10-02 |
451770 | UNKNOWN in v8::internal::SharedFunctionInfo::code | - | 2016-10-02 |
451799 | Heap overflow and integer overflow in ICU library | $500 | 2016-10-02 |
451755 | UNKNOWN in content::WebContentsImpl::OnOpenColorChooser | - | 2016-10-02 |
451058 | Use-of-uninitialized-value in blink::HarfBuzzShaper::HarfBuzzShaper | - | 2016-10-02 |
450844 | Heap-buffer-overflow in opj_dwt_decode_1 | $1,000 | 2016-10-02 |
450654 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
451059 | Heap-use-after-free in blink::RenderObject::setNeedsLayout | - | 2016-10-02 |
450939 | Negative-size-param in vp9_dec_setup_mi | $1,000 | 2016-10-02 |
451509 | Heap-buffer-overflow in Pickle::WriteData | - | 2016-10-02 |
451456 | Heap-use-after-free in content::GpuChannelHost::DestroyChannel() | $500 | 2016-10-02 |
450389 | Use-of-uninitialized-value in SkPreMultiplyARGB | $1,000 | 2016-10-02 |
450198 | Adobe Flash Player Out-of-Bound Access Vulnerability | $2,000 | 2016-10-02 |
450096 | Heap-use-after-free in base::internal::DiscardableMemoryShmem::AllocateAndAcquireLock | - | 2016-10-02 |
450653 | UNKNOWN in blink::InlineTextBox::isLineBreak | - | 2016-10-02 |
450642 | UNKNOWN in v8::internal::Code::deoptimization_data | - | 2016-10-02 |
450391 | Security: aarch64 seccomp lacks ability to redirect syscalls | - | 2016-10-02 |
450038 | Heap-buffer-overflow in blink::BidiResolver<blink::InlineIterator, blink::BidiRun>::applyL1Rule | - | 2016-10-02 |
449845 | Use-of-uninitialized-value in CFX_ByteString::FormatInteger | - | 2016-10-02 |
449829 | Security: Illegal domain name resolving using leading dot creating unexpected behaviour/URL Bar Spoofing | $1,000 | 2016-10-02 |
449777 | UNKNOWN in content::WebContentsImpl::OnOpenColorChooser | - | 2016-10-02 |
449739 | Security: Heap-use-after-free SpeechRecognitionDispatcher | $1,000 | 2016-10-02 |
449610 | ZDI-CAN-2662: Google Chrome V8EventListenerList::findOrCreateWrapper Type Confusion Remote Code Execution Vulnerability | - | 2016-10-02 |
449893 | Heap-buffer-overflow in media::AudioBus::SwapChannels | - | 2016-10-02 |
449958 | Heap-buffer-overflow in media::CopyPlane | $2,000 | 2016-10-02 |
449049 | Heap-use-after-free in blink::WorkerSharedTimer::setFireInterval | - | 2016-10-02 |
449047 | Use-after-free in blink::Canvas2DLayerBridge::mailboxReleased | - | 2016-10-02 |
449045 | Heap-use-after-free in blink::NavigationScheduler::shouldScheduleNavigation | - | 2016-10-02 |
448798 | Use-of-uninitialized-value in IPC::ChannelPosix::ProcessOutgoingMessages | - | 2016-10-02 |
449574 | Heap-use-after-free in extensions::MimeHandlerViewContainer::OnMessageReceived | - | 2016-10-02 |
449291 | Global-buffer-overflow in v8::internal::MarkCompactCollector::EmptyMarkingDeque | - | 2016-10-02 |
448423 | Heap-buffer-overflow in SkData::NewUninitialized | $5,000 | 2016-10-02 |
448314 | Heap-use-after-free in blink::V8PerContextData::constructorForTypeSlowCase | $3,000 | 2016-10-02 |
448189 | Wild read in aura::GetDeviceScaleFactorFromDisplay | - | 2016-10-02 |
448102 | Bad-cast to v8::internal::OFStreamBase from base class subobject at offset 8;ostreams.cc:27:37 | - | 2016-10-02 |
448082 | Heap-use-after-free in content::ServiceWorkerScriptCacheMap::NotifyFinishedCaching | $2,500 | 2016-10-02 |
448081 | Heap-use-after-free in blink::FrameLoaderClientImpl::allowScript | - | 2016-10-02 |
448428 | Heap-use-after-free in /usr/lib/libstdc++.6.dylib+0x2dfc9 | - | 2016-10-02 |
448299 | Heap-buffer-overflow in sk_memset32_SSE2 | - | 2016-10-02 |
448056 | UNKNOWN in content::WebContentsImpl::OnDidStartLoading | - | 2016-10-02 |
448006 | Heap-use-after-free in blink::Node::compareDocumentPosition | $3,000 | 2016-10-02 |
447976 | Heap-use-after-free in blink::ScopedStyleResolver::collectMatchingAuthorRules | $3,000 | 2016-10-02 |
447906 | Heap-use-after-free in blink::DateTimeEditElement::~DateTimeEditElement | $5,000 | 2016-10-02 |
447889 | Global-buffer-overflow in hb_indic_get_categories | - | 2016-10-02 |
447860 | global-buffer-overflow at vp56_rac_get_prob_branchy | $500 | 2016-10-02 |
448057 | Use-of-uninitialized-value in extract_image_data | - | 2016-10-02 |
448061 | ASSERTION FAILED: !object || (object->isText()) | - | 2016-10-02 |
448008 | Select/option website clickjacking | - | 2016-10-02 |
447852 | Vulnerability reported in dev-libs/openssl | - | 2016-10-02 |
458777 | Heap-use-after-free in blink::Frame::host | - | 2016-10-02 |
458776 | Heap-use-after-free in blink::WebPluginContainerImpl::scriptableObject | - | 2016-10-02 |
458868 | Heap-use-after-free in content::ChildThreadImpl::ShutdownThread | - | 2016-10-02 |
458861 | Heap-buffer-overflow in chromium_ijg_jpeg_idct_islow | - | 2016-10-02 |
457480 | Heap-buffer-overflow in opj_dwt_decode | $3,000 | 2016-10-02 |
458184 | Use-after-free in blink::LayoutObject::isRooted | - | 2016-10-02 |
458024 | [qcms] security - stack buffer overread in lut_inverse_interp16 | - | 2016-10-02 |
457680 | Security: Flash AS2 Use After Free in DisplacementMapFilter.mapBitmap | $5,000 | 2016-10-02 |
457583 | Security: Flash AS2 ConvolutionFilter Uninitialized Memory Leak | $4,000 | 2016-10-02 |
457493 | Heap-double-free in j2k_read_ppm_v3 | $2,000 | 2016-10-02 |
458026 | [qcms] security - heap info leak in qcms | - | 2016-10-02 |
458474 | Heap-use-after-free in net::FileStream::Context::ReadAsyncResult | - | 2016-10-02 |
458191 | Heap-use-after-free in blink::HTMLImportTreeRoot::recalcTimerFired | - | 2016-10-02 |
456920 | Heap-use-after-free in base::ElapsedTimer::Elapsed | - | 2016-10-02 |
456841 | Security: Extensions can silently debug (run code) in ANY tab and escape the sandbox | $1,000 | 2016-10-02 |
456828 | Security: heap-buffer-overflow in SkGradientShaderBase::SkGradientShaderBase | $5,000 | 2016-10-02 |
457278 | Security: Flash AS2 Use After Free in TextField.filters | $5,000 | 2016-10-02 |
456635 | Heap-use-after-free in blink::Node::compareDocumentPosition | - | 2016-10-02 |
456532 | Heap-use-after-free in blink::UserMediaRequest::start | - | 2016-10-02 |
456516 | Security: MidiHostMsg_SendData vector OOB on Android | $7,500 | 2016-10-02 |
456391 | Don't supply invalid hostnames to the DNS resolver | - | 2016-10-02 |
456206 | Heap-buffer-overflow in parse_encoding | $500 | 2016-10-02 |
456192 | Possibly invalid type cast in blink::V8LazyEventListener::prepareListenerObject | $3,000 | 2016-10-02 |
456636 | Use-of-uninitialized-value in blink::CustomElementUpgradeCandidateMap::~CustomElementUpgradeCandidateMap | - | 2016-10-02 |
456101 | Security: Race condition in Flash workers may cause an exploitable double free by abusing bytearray.writeObject | $7,500 | 2016-10-02 |
456059 | Heap-use-after-free in blink::PendingScript::stopWatchingForLoad | $3,000 | 2016-10-02 |
455964 | Security: NaCl process are not marked non-dumpable. | - | 2016-10-02 |
455953 | Security: file:// origins can use webkitRequestFullscreen and requestPointerLock without a prompt | - | 2016-10-02 |
455857 | Google Chrome SpeechRecognitionClient Use-After-Free Remote Code Execution Vulnerability | - | 2016-10-02 |
455839 | Security: NaCl processes should have an address space usage limit | - | 2016-10-02 |
455994 | double free at content::RenderFrameImpl::~RenderFrameImpl | - | 2016-10-02 |
455428 | Password is read out in the 'connect to corp network' window | - | 2016-10-02 |
455368 | UNKNOWN in blink::SQLStatementBackend::execute | $2,500 | 2016-10-02 |
455215 | Security: HSTS not applied to WebSocket | $500 | 2016-10-02 |
454426 | Use-of-uninitialized-value in FT_RoundFix | - | 2016-10-02 |
454280 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
454278 | Use-after-free in media::CdmSessionAdapter::Initialize | - | 2016-10-02 |
454268 | Heap-buffer-overflow in PPP_GetInterface | - | 2016-10-02 |
454231 | Heap Use After Free @blink::BaseMultipleFieldsDateAndTimeInputType::readonlyAttributeChanged | $2,000 | 2016-10-02 |
455735 | UNKNOWN in blink::WebSpeechSynthesisVoice::operator | $2,000 | 2016-10-02 |
455363 | Heap-buffer-overflow in ps_table_add | - | 2016-10-02 |
453994 | Security: GaiaAuthExtension is too powerful and should validate parameter | - | 2016-10-02 |
452794 | Heap-use-after-free in CPDFSDK_Widget::GetMixXFAWidget | - | 2016-10-02 |
453553 | SIGSEGV in opj_j2k_update_image_data via pdfium_test | - | 2016-10-02 |
453279 | Heap-use-after-free in blink::MutationObserverRegistration::unregister | $3,000 | 2016-10-02 |
453209 | Use-after-poison in blink::ThreadHeap::allocate+0x58 | - | 2016-10-02 |
453126 | Undefined behavior (bad virtual call) in net/socket/ssl_client_socket_pool.cc | - | 2016-10-02 |
454153 | Global-buffer-overflow in blink::AXRenderObject::text | - | 2016-10-02 |
452793 | Heap-use-after-free in FT_Stream_ReleaseFrame | - | 2016-10-02 |
454157 | Use-of-uninitialized-value in void v8::internal::ScavengingVisitor< | - | 2016-10-02 |
453979 | Security: UXSS in V8 | - | 2016-10-02 |
452135 | ASSERTION FAILED: !m_renderGrid.gridIsDirty() in blink::GridPainter::paintChildren | - | 2016-10-02 |
452059 | Copy-Paste XSS (ODT to contenteditable) | - | 2016-10-02 |
452638 | Heap-use-after-free in content::RenderFrameImpl::DecidePolicyForNavigation | - | 2016-10-02 |
452455 | Heap-buffer-overflow in CPDF_SampledFunc::v_Call | - | 2016-10-02 |
464409 | Update net-misc/radsecproxy to 1.6.6 | - | 2016-10-02 |
464391 | Heap-use-after-free in base::internal::CallbackBase::Reset | - | 2016-10-02 |
464463 | Use-of-uninitialized-value in content::BrowserMessageFilter::Send | - | 2016-10-02 |
464594 | Use-of-uninitialized-value in content::BrowserMessageFilter::Send | - | 2016-10-02 |
463958 | Heap-use-after-free in xmlSwitchEncoding | $1,000 | 2016-10-02 |
463920 | Heap-use-after-free in SuperBlitter::blitH | - | 2016-10-02 |
463599 | Heap-buffer-overflow in blink::WebString::fromUTF8 | $1,000 | 2016-10-02 |
462843 | Security: UXSS in AuthenticatorHelper | $7,500 | 2016-10-02 |
462300 | Heap-buffer-overflow in resize_context_buffers | - | 2016-10-02 |
461936 | Heap-use-after-free in gcm::GCMClientImpl::OnRegisterCompleted | - | 2016-10-02 |
461858 | Chrome allows "Always open files of this type" to be used with executables | $500 | 2016-10-02 |
462319 | Heap-use-after-free in gcm::SocketInputStream::Refresh | - | 2016-10-02 |
461474 | UNKNOWN in bool blink::outputRows< | - | 2016-10-02 |
461191 | Security: UNKNOWN in RenderFrameImpl::OnMessageReceived | $3,000 | 2016-10-02 |
461481 | Security: HSTS bypass | $1,000 | 2016-10-02 |
460939 | Heap-use-after-free in content::GLHelper::CopyTextureToImpl::FinishRequest | - | 2016-10-02 |
460938 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
460937 | UNKNOWN in v8::internal::IC::SetTargetAtAddress | - | 2016-10-02 |
460936 | Use-of-uninitialized-value in FT_DivFix | - | 2016-10-02 |
460917 | OOB write in v8 due to elements kind confusion | $500 | 2016-10-02 |
461472 | Heap-use-after-free in blink::PopupMenuImpl::didClosePopup | - | 2016-10-02 |
460751 | Use-after-free in blink::ColorInputType::didEndChooser | - | 2016-10-02 |
460426 | Add RELEASE_ASSERTs to ScriptRunner to crash in a more controlled way? | - | 2016-10-02 |
460391 | Search query highlights the scheme of the search term and displays like a URL | - | 2016-10-02 |
460145 | Unsafe %GeneratorFuntion% intrinsic cannot be denied | - | 2016-10-02 |
459898 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | - | 2016-10-02 |
459897 | Use-of-uninitialized-value in SkConic::computeQuadPOW2 | - | 2016-10-02 |
460752 | Heap-use-after-free in blink::Document::didChangeVisibilityState | - | 2016-10-02 |
460431 | Regression: Chrome crashes when "No thanks" link is dropped in any text-boxes on Chrome sign-in page. | - | 2016-10-02 |
459637 | Use-of-uninitialized-value in v8::internal::compiler::Schedule::block | - | 2016-10-02 |
459633 | Use-after-poison in v8::internal::compiler::Node::Input::Update | - | 2016-10-02 |
459632 | Bad parameters to __sanitizer_annotate_contiguous_container in blink::EventListenerMap::EventListenerMap | - | 2016-10-02 |
459564 | XSS in chrome://webrtc-internals/ | - | 2016-10-02 |
459533 | Heap-use-after-free in blink::LayoutLayerModelObject::hasSelfPaintingLayer | $2,000 | 2016-10-02 |
459483 | Use-of-uninitialized-value in sha1_final | - | 2016-10-02 |
459445 | Security: Url Bar Spoofing using the redirections at shopping.paypal.com | - | 2016-10-02 |
459862 | Heap-use-after-free in blink::VectorMath::zvmul | - | 2016-10-02 |
458871 | Use-of-uninitialized-value in blink::RenderView::setSelection | - | 2016-10-02 |
459215 | Security: pdfium - write past end of heap buffer when parsing invalid JPEG2000 image | $3,000 | 2016-10-02 |
459114 | Heap-use-after-free in get_lowest_part_y | - | 2016-10-02 |
459043 | Chrome_Mac: Crash Report - blink::HarfBuzzShaper::setGlyphPositionsForHarfBuzzRun | - | 2016-10-02 |
458876 | Use-of-uninitialized-value in v8::internal::compiler::Schedule::block | $1,000 | 2016-10-02 |
458875 | Global-buffer-overflow in cff_parse_real | - | 2016-10-02 |
458873 | Heap-buffer-overflow in bloat_quad | - | 2016-10-02 |
459115 | Heap-use-after-free in content::MessagePortService::UpdateMessagePort | - | 2016-10-02 |
459239 | Heap-use-after-free in base::ElapsedTimer::Elapsed | - | 2016-10-02 |
458870 | Heap-use-after-free in blink::TreeScopeStyleSheetCollection::analyzeStyleSheetChange | - | 2016-10-02 |
458869 | UNKNOWN in TLine::GetMappedCharsInRange | - | 2016-10-02 |
469395 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
469305 | Update sqlite to uptake http://www.sqlite.org/src/info/ceebcdcaf1acf409 | - | 2016-10-02 |
469247 | Use-of-uninitialized-value in blink::TransformationMatrix::blend | - | 2016-10-02 |
469244 | Stack-buffer-overflow in CFX_WideString::FormatV | $1,000 | 2016-10-02 |
469152 | P2PSocketDispatcherHost UaF | - | 2016-10-02 |
469151 | GamepadProvider infoleak | - | 2016-10-02 |
469148 | UNKNOWN in v8::internal::ExternalUint32Array::SetValue | - | 2016-10-02 |
469082 | Security: sqlite bad ptr access | - | 2016-10-02 |
468972 | Security: Two DoS bugs from OpenSSL 1.0.2a security advisory. | - | 2016-10-02 |
468936 | Pwn2own gpu bug | - | 2016-10-02 |
468931 | Security: Webpages have access to some extension resources | $3,000 | 2016-10-02 |
468933 | Security: pwn2own 2015 exploit #1 | - | 2016-10-02 |
468618 | ASSERTION FAILED: !value || (value->isValueList()) | - | 2016-10-02 |
468451 | Some cross-origin `location` properties are accessible | $3,000 | 2016-10-02 |
468179 | Alert popup with no and/or inaccurate origin identification | $500 | 2016-10-02 |
468167 | Use-of-uninitialized-value in parse_font_matrix | $1,000 | 2016-10-02 |
468519 | Container-overflow in blink::FEColorMatrix::createImageFilter | $1,500 | 2016-10-02 |
468406 | Container-overflow in blink::HTMLTreeBuilder::processStartTagForInBody | - | 2016-10-02 |
467644 | Bad-cast to blink::LayoutBox from blink::LayoutText;LayoutBox.h:NUMBER:1 | - | 2016-10-02 |
467452 | Heap-use-after-free in blink::Node::recalcDistribution | $2,000 | 2016-10-02 |
467481 | UNKNOWN in v8::base::NoBarrier_Load | - | 2016-10-02 |
467844 | Hosted apps running in windows don't show the origin. | - | 2016-10-02 |
468166 | Use-of-uninitialized-value in blink::Member<blink::IDBKey>* blink::HeapAllocator::allocateVectorBacking<b | $1,500 | 2016-10-02 |
467593 | UNKNOWN in SkBlitMask::RowFactory | - | 2016-10-02 |
467352 | UNKNOWN in gleUnbindDeleteHashNamesAndObjects | - | 2016-10-02 |
467347 | UNKNOWN in SkBlitLCD16OpaqueRow_SSE2 | - | 2016-10-02 |
467184 | Use-of-uninitialized-value in cc::LayerQuad::ToQuadF | - | 2016-10-02 |
467014 | Heap-use-after-free in blink::LayoutObject::container | - | 2016-10-02 |
467372 | Heap-use-after-free in base::MessageLoop::DeleteSoonInternal | - | 2016-10-02 |
467348 | Heap-use-after-free in blink::TextFieldInputType::handleKeydownEventForSpinButton | $1,500 | 2016-10-02 |
466990 | Heap-use-after-free in hb_ot_map_t::lookup_map_t::cmp | - | 2016-10-02 |
466967 | UNKNOWN in sk_memset32_SSE2 | $1,000 | 2016-10-02 |
466790 | Global-buffer-overflow in CPDF_CIDFont::_CharCodeFromUnicode | - | 2016-10-02 |
466338 | Security: Unchecked memcpy in _png_load_bmp_attribute() | - | 2016-10-02 |
466632 | Heap-use-after-free in v8::internal::Code::Disassemble | - | 2016-10-02 |
466351 | Security: On Android, it's possible to inject text and icons to the page info bubble using crafted URL fragments | $500 | 2016-10-02 |
467011 | Heap-buffer-overflow in SkAAClipBlitter::blitMask | - | 2016-10-02 |
465557 | Security: Browser-process out-of-bounds write of up to 7 bytes in BoringSSL ssl3_read_n. | - | 2016-10-02 |
465586 | Use-after-free in _XReply | - | 2016-10-02 |
466335 | Heap-use-after-free in content::WebSocketHost::AddChannel | - | 2016-10-02 |
465759 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-02 |
465517 | Origin header preserved for cross-origin redirects with 307 status code, should be null | - | 2016-10-02 |
465002 | UNKNOWN in PluginObserver::PluginPlaceholderHost::DownloadFinished | - | 2016-10-02 |
464995 | Heap-use-after-free in webrtc::DtlsIdentityStore::GenerateIdentity_w | - | 2016-10-02 |
464871 | Flash: use-after-free in display list handling from KeenTeam (repros 2-5, 6) | $4,000 | 2016-10-02 |
464870 | Flash: use-after-free in display list handling from KeenTeam (repro 1) | $3,000 | 2016-10-02 |
464792 | Heap-use-after-free in blink::FrameView::setScrollbarModes | - | 2016-10-02 |
465426 | Heap-use-after-free in get_lowest_part_y | - | 2016-10-02 |
465185 | Heap-use-after-free in std::_Tree<std::_Tset_traits<enum | - | 2016-10-02 |
465091 | Heap-buffer-overflow in blink::Document::Document | - | 2016-10-02 |
474609 | Heap-use-after-free in blink::HTMLImportTreeRoot::recalcTimerFired | - | 2016-10-02 |
474784 | Heap-use-after-free in blink::ScriptStreamer::streamingCompleteOnBackgroundThread | - | 2016-10-02 |
474783 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
474370 | Security: heap-use-after-free in content::MediaStreamDispatcher::OnStreamGenerated | $1,000 | 2016-10-02 |
474254 | Merge change to reject DHE for False Start | - | 2016-10-02 |
474099 | Security: Use-after-free in webaudio/scriptprocessornode-premature-death.html and webaudio/scriptprocessornode-premature-death.html | - | 2016-10-02 |
474297 | UNKNOWN in v8::internal::PropertyCell::UpdateCell | - | 2016-10-02 |
473688 | Heap-buffer-overflow in media::MultiChannelResampler::Resample | - | 2016-10-02 |
473253 | Security: heap-use-after-free in blink::ConsumerWrapper::consumeAudio | $3,000 | 2016-10-02 |
474082 | Container-overflow in TabDragController::GetTabsMatchingDraggedContents | - | 2016-10-02 |
474077 | UNKNOWN in v8::internal::NativeRegExpMacroAssembler::Execute | - | 2016-10-02 |
473903 | Clicking 'prevent additional dialogs' fails to work with some scammer sites | - | 2016-10-02 |
472613 | Heap-buffer-overflow in blink::UTF16TextIterator::consumeSlowCase | $500 | 2016-10-02 |
472201 | Security: Flash: Uninitialized stack variable while parsing an MPD file can corrupt memory | $3,000 | 2016-10-02 |
472147 | Heap-buffer-overflow in SuperBlitter::blitH | - | 2016-10-02 |
472146 | Heap-use-after-free in printing::PrintJobWorker::GetSettingsWithUIDone | - | 2016-10-02 |
471991 | Global-buffer-overflow in CXFA_ItemLayoutProcessor::CalculatePositionedContainerPos | - | 2016-10-02 |
471990 | UNKNOWN in CPDF_SampledFunc::v_Call | - | 2016-10-02 |
472614 | Heap-use-after-free in content::IndexedDBBackingStore::Transaction::ChainedBlobWriterImpl::ReportW | $3,500 | 2016-10-02 |
472618 | WebSQL shoudn't run a nested message loop during renderer shutdown. | - | 2016-10-02 |
472617 | Heap-use-after-free in content::UserMediaClientImpl::OnCreateNativeTracksCompleted | - | 2016-10-02 |
471651 | Heap-buffer-overflow in CPDF_CMap::GetNextChar | $500 | 2016-10-02 |
471525 | Heap-buffer-overflow in url::ParsePort | $1,000 | 2016-10-02 |
471523 | Security: Heap-use-after-free in extensions::`anonymous namespace'::LoadWatcher::DidCreateDocumentElement+68 | $3,000 | 2016-10-02 |
471445 | Bad-cast to blink::LayoutMultiColumnFlowThread from blink::LayoutTable;LayoutBlockFlow.cpp:3089:13 | - | 2016-10-02 |
471785 | Bad-cast to blink::DedicatedWorkerGlobalScope from blink::CompositorWorkerGlobalScope;WorkerMessagingProxy.cpp:76:47 | - | 2016-10-02 |
471652 | NO STACK | - | 2016-10-02 |
470980 | Security: Unknown in convolve4RowsHorizontally_SSE2 | - | 2016-10-02 |
471000 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
470837 | Security: Flash Player Integer Overflow in Function.apply | $7,500 | 2016-10-02 |
470777 | Heap-buffer-overflow in blink::WebSpeechRecognitionHandle::operator blink::SpeechRecognition* | - | 2016-10-02 |
471072 | UNKNOWN in S32A_Opaque_BlitRow32_SSE4 | - | 2016-10-02 |
470864 | Security: Use After Free in Flash AVSS.setSubscribedTags can cause memory corruption | $5,000 | 2016-10-02 |
470856 | Use-of-uninitialized-value in webrtc::internal::TransportAdapter::SendRTCPPacket | - | 2016-10-02 |
470470 | Heap-use-after-free in blink::PopupMenuImpl::addElementStyle | - | 2016-10-02 |
470391 | Use-of-uninitialized-value in v8::internal::Simulator::LoadStoreHelper | - | 2016-10-02 |
470390 | UNKNOWN in v8::internal::Heap::UpdateAllocationSiteFeedback | - | 2016-10-02 |
470749 | Flash: bad cast(?) in display list handling from KeenTean | $2,000 | 2016-10-02 |
470392 | UNKNOWN in v8::internal::FixedArray::get | - | 2016-10-02 |
470753 | Flash: out-of-bounds write in shader handling | $3,000 | 2016-10-02 |
470751 | Flash: AGAL information leak from KeenTeam | $1,000 | 2016-10-02 |
470121 | Bad-cast to webrtc::newapi::Transport from invalid vptr;transport_adapter.cc:36:18 | - | 2016-10-02 |
469814 | Looks like OOB call in memcpy | - | 2016-10-02 |
470144 | Heap-use-after-free in ImageDecoder::OnMessageReceived | - | 2016-10-02 |
469743 | UNKNOWN in libc.so.6 | - | 2016-10-02 |
469507 | Security: Screen contents from other origins and non-Chrome applications are displayed in the browser | $1,000 | 2016-10-02 |
469480 | NO STACK | $3,500 | 2016-10-02 |
470128 | UNKNOWN in v8::internal::TypeFeedbackOracle::CanRetainOtherContext | - | 2016-10-02 |
470122 | Heap-use-after-free in webrtc::internal::TransportAdapter::SendRTCPPacket | - | 2016-10-02 |
469756 | Use-of-uninitialized-value in blink::TransformationMatrix::rotate3d | - | 2016-10-02 |
469416 | Container-overflow in content::MidiMessageFilter::HandleClientAdded | - | 2016-10-02 |
481874 | Vulnerability reported in net-dialup/ppp | - | 2016-10-02 |
481299 | OS X memory corruption in IOAccelSurface2::set_shape_backing_length_ext from KEEN Team | $5,000 | 2016-10-02 |
481298 | OS X memory corruption in IGFence::release from KEEN Team | $5,000 | 2016-10-02 |
481296 | Apple OS X Yosemite 10.10.2 IOAccelSurface2::set_id_mode OOB read on IOAccelMachine2 from KEEN Team | $5,000 | 2016-10-02 |
481218 | OS X kASLR defeat from KEEN Team | $4,000 | 2016-10-02 |
481044 | Security: use-after-free in WebAudio | - | 2016-10-02 |
481015 | Security: XSS in the bookmark button | $500 | 2016-10-02 |
481639 | Security: Boundless Tunes - universal SOP bypass through ActionSctipt's Sound object | $7,500 | 2016-10-02 |
481306 | Flash use-after-free in display list handling from KEEN Team, round #2 | $3,000 | 2016-10-02 |
480536 | Container-overflow in /mnt/scratch0/clusterfuzz/slave-bot/builds/chromium-browser-asan_linux-rele | - | 2016-10-02 |
479825 | Use-after-free in blink::LayoutMenuList::setIndexToSelectOnCancel | - | 2016-10-02 |
479427 | ASSERTION FAILED: !object || (object->isLayoutBlock()) | - | 2016-10-02 |
479743 | Security: 1503A - Chrome - ui::AXTree::Unserialize UAF | - | 2016-10-02 |
480201 | Security: chrome url spoofing | $1,000 | 2016-10-02 |
478745 | Heap-use-after-free in blink::ContainerNode::addChildNodesToDeletionQueue | - | 2016-10-02 |
478575 | Heap-use-after-free in blink::Node::parentOrShadowHostOrTemplateHostNode | - | 2016-10-02 |
478578 | Heap-use-after-free in cc::ScrollbarLayerImplBase::PushScrollClipPropertiesTo | - | 2016-10-02 |
479162 | Security: spell checking dictionaries are fetched over HTTP, and large responses lead to a crash | $500 | 2016-10-02 |
478556 | UNKNOWN in v8::internal::ExecutableAccessorInfo::set_setter | - | 2016-10-02 |
478549 | Heap-use-after-free in blink::SMILTimeContainer::updateAnimations | $2,000 | 2016-10-02 |
478583 | Use-of-uninitialized-value in content::MediaInternals::OnMediaEvents | - | 2016-10-02 |
478009 | UNKNOWN in v8::internal::PropertyCell::PropertyCellVerify | - | 2016-10-02 |
478077 | Heap-use-after-free in v8::internal::CompilationDependencies::Abort | - | 2016-10-02 |
477953 | UNKNOWN in v8::internal::JSObject::JSObjectVerify | - | 2016-10-02 |
477868 | Decide on security style for resources loaded over bad HTTPS with user exception | - | 2016-10-02 |
477955 | UNKNOWN in v8::internal::FixedArray::FixedArrayVerify | - | 2016-10-02 |
477331 | Negative-size-param in cc::ListContainer<cc::DrawQuad>::EraseAndInvalidateAllPointers | - | 2016-10-02 |
477333 | ASSERTION FAILED: node.isElementNode() | - | 2016-10-02 |
477380 | Bad-cast to blink::RawResourceClient from blink::LinkLoader;RawResource.cpp:59:33 | - | 2016-10-02 |
477680 | Security: avatars are fetched over HTTP, and large responses lead to a crash | - | 2016-10-02 |
477713 | ASSERTION FAILED: !needsLayout | - | 2016-10-02 |
477819 | Heap-use-after-free in blink::FFTFrame::doInverseFFT | - | 2016-10-02 |
477298 | UNKNOWN in v8::internal::HeapObject::SizeFromMap | - | 2016-10-02 |
477278 | Security: URL spoof message of onbeforeunload | - | 2016-10-02 |
476926 | Security: Flash AS2 Use After Free in TextField.filters (again) | $5,000 | 2016-10-02 |
477089 | Heap-use-after-free in void blink::ScriptPromiseResolver::resolveOrReject<blink::AudioBuffer*> | - | 2016-10-02 |
476647 | Use-of-uninitialized-value in SkRecords::FillBounds::adjustAndMap | $500 | 2016-10-02 |
476107 | Heap-buffer-overflow in CJBig2_Context::parseSymbolDict | - | 2016-10-02 |
477187 | Heap-use-after-free in blink::AudioScheduledSourceHandler::notifyEnded | - | 2016-10-02 |
475749 | Heap-buffer-overflow in media::ChannelMixingMatrix::CreateTransformationMatrix | - | 2016-10-02 |
475773 | Heap-use-after-free in blink::LayoutBox::contentBoxRect | - | 2016-10-02 |
475070 | Security: Clank injects JavaScript into the main page's world | - | 2016-10-02 |
475018 | Security: [FLASH] Issues in DefineBitsLossless and DefineBitsLossless2 leads to using uninitialized memory while rendering a picture | $4,000 | 2016-10-02 |
489764 | boringssl: x509v3 has possible use-after-free in do_check_string() | - | 2016-10-02 |
488783 | Heap-buffer-overflow in url::CanonicalizeIPAddress | - | 2016-10-02 |
489151 | UNKNOWN in v8::internal::Simulator::LoadStoreHelper | - | 2016-10-02 |
487284 | Security: QCMS crash OOB read at src/chain.c:211 | - | 2016-10-02 |
487752 | Unsecure shared memory | - | 2016-10-02 |
487286 | Negative-size-param in content::AppCacheUpdateJob::OnDestructionImminent | - | 2016-10-02 |
487928 | Heap-use-after-free in CJS_WideStringArray::~CJS_WideStringArray | $4,337 | 2016-10-02 |
486947 | UNKNOWN in SkReader32::readString | $5,000 | 2016-10-02 |
486946 | UNKNOWN in _fini | $5,000 | 2016-10-02 |
487237 | Security: Flash AS2 Use After Free in DisplacementMapFilter.mapBitmap | $5,000 | 2016-10-02 |
486944 | Stack-buffer-overflow in SkPackBits::Unpack8 | $5,000 | 2016-10-02 |
486538 | Heap-double-free in opj_j2k_tcp_destroy | - | 2016-10-02 |
487155 | Security: CSP does not block svg image in nested iframe | $1,000 | 2016-10-02 |
486977 | Heap-buffer-overflow in SkData::NewUninitialized | $5,000 | 2016-10-02 |
486945 | Heap-double-free in SkPictureData::~SkPictureData | $5,000 | 2016-10-02 |
486434 | Stack-buffer-overflow in sandbox::BrokerServicesBase::SpawnTarget | $2,500 | 2016-10-02 |
486003 | UNKNOWN in v8::internal::Heap::EnsureDoubleAligned | - | 2016-10-02 |
486000 | Heap-use-after-free in blink::LayoutMultiColumnSet::updateMinimumColumnHeight | - | 2016-10-02 |
485893 | Security: Adobe Flash FLV SCRIPTDATDSTRING OOB read Information Leak | - | 2016-10-02 |
486301 | Heap-use-after-free in blink::BMPImageReader::decodeBMP | - | 2016-10-02 |
486004 | Heap-use-after-free in base::MessageLoop::PostTask | - | 2016-10-02 |
485843 | Use-after-poison in blink::PlatformSpeechSynthesizer::setVoiceList | - | 2016-10-02 |
485419 | UNKNOWN in v8::internal::Simulator::DecodeTypeImmediate | - | 2016-10-02 |
485414 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
485413 | Heap-use-after-free in ExtensionLocalizationPeer::OnCompletedRequest | - | 2016-10-02 |
485534 | Heap-use-after-free in v8::internal::JSObject::PrintElements | - | 2016-10-02 |
485198 | XSS Auditor bypass: <link rel="import {garbage}" | - | 2016-10-02 |
484998 | An integer overflow in libskia could be used to escalate from Chrome's sandbox in Android | $3,000 | 2016-10-02 |
484957 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
485855 | Heap-use-after-free in /mnt/scratch0/clusterfuzz/slave-bot/builds/chromium-browser-asan_linux-release/r | - | 2016-10-02 |
485412 | Heap-buffer-overflow in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
484610 | Security: Flash UAF with Color.setRGB in AS2 | $7,500 | 2016-10-02 |
484432 | Potential heap overflow in WebRTC's VCMEncodedFrame | - | 2016-10-02 |
484270 | Security: Heap overflow in CertificateResourceHandler | - | 2016-10-02 |
484211 | Apply upstream EAP-PWD, WPS and WMM fixes | - | 2016-10-02 |
484614 | Heap-use-after-free in blink::CSSAnimations::maybeApplyPendingUpdate | $3,000 | 2016-10-02 |
483981 | Security: Heap Overflow Vulnerability in JBIG2 handling, used by PDF Reader | $5,500 | 2016-10-02 |
483923 | Use-of-uninitialized-value in SkRect::join | - | 2016-10-02 |
483728 | UNKNOWN in v8::internal::RelocIterator::RelocIterator | - | 2016-10-02 |
483727 | Heap-use-after-free in blink::InspectorResolver::resolveFrame | - | 2016-10-02 |
483488 | Security: Service Workers let you bypass some same-origin checks (like verbose script parsing errors) | - | 2016-10-02 |
483375 | Security: [FG-VD-15-037] Adobe Flash Player PCRE Handing Heap Overflow Vulnerability | $3,000 | 2016-10-02 |
483340 | Heap-buffer-overflow in blink::RejectedPromises::processQueue | - | 2016-10-02 |
482639 | UNKNOWN in CJBig2_HuffmanTable::parseFromCodedBuffer | - | 2016-10-02 |
482521 | Security: Flash UAF with MovieClip.scrollRect in AS2 | $7,500 | 2016-10-02 |
483856 | Use-after-poison in blink::PendingScript::PendingScript | - | 2016-10-02 |
482369 | ASSERTION FAILED: !entry->element || entry->element == element | - | 2016-10-02 |
482380 | Security: URL Spoof with http authentication dialog and pdf prompt dialog | $500 | 2016-10-02 |
482214 | ASSERTION FAILED: !object || (object->isBox()) | $2,500 | 2016-10-02 |
498982 | Security: XSS Auditor info disclosure using iframe length from different domains | $1,337 | 2016-10-02 |
498954 | Heap-use-after-free in content::BrowserPlugin::~BrowserPlugin | - | 2016-10-02 |
498478 | Proximity Auth Base64URL decoding allows invalid messages through | - | 2016-10-02 |
498475 | Heap-use-after-free in blink::InspectorDebuggerAgent::removeBreakpoint | - | 2016-10-02 |
498338 | Security: Integer Overflow in Windows Sandbox Policy Engine String Comparison | - | 2016-10-02 |
497632 | Security: SEGV on unknown address in offsetHeightAttributeGetter | $3,000 | 2016-10-02 |
497588 | Security: Chrome Address Spoofing with unresponsive page | - | 2016-10-02 |
497579 | ASSERTION FAILED: offset + length <= m_length | - | 2016-10-02 |
498984 | Security: Flash AS2 Use After Free in TextField.filters (again and again) | $5,000 | 2016-10-02 |
497576 | UNKNOWN in v8::internal::ArrayConcatVisitor::ToArray | - | 2016-10-02 |
497523 | ASSERTION FAILED: !value || (value->isGridLineNamesValue()) | - | 2016-10-02 |
497578 | Heap-buffer-overflow in gfx::internal::TextRunHarfBuzz::GetClusterAt | - | 2016-10-02 |
497507 | Security: Cross-origin scripting possible via native functions | $7,500 | 2016-10-02 |
497435 | Heap-use-after-free in blink::LayoutMultiColumnSet::pageLogicalHeight | - | 2016-10-02 |
497357 | Heap-buffer-overflow in color_sycc_to_rgb | $1,000 | 2016-10-02 |
497355 | Heap-double-free in j2k_read_ppm_v3 | $3,000 | 2016-10-02 |
497195 | ASSERTION FAILED: !object || (object->isLayoutMultiColumnSet()) | - | 2016-10-02 |
497524 | Use-after-free in WTF::Vector<blink::MultiColumnFragmentainerGroup,1,WTF::DefaultAllocator>::at | - | 2016-10-02 |
495933 | Security: RTL character + IP address = spoofed domain | - | 2016-10-02 |
495682 | Use-of-uninitialized-value in /mnt/scratch0/clusterfuzz/slave-bot/builds/linux_msan_chrome_ipc/custom/msan_ipc | - | 2016-10-02 |
495300 | Security: heap-use-after-free in pdfium CFX_BaseSegmentedArray | - | 2016-10-02 |
494987 | Security: Geolocation API Spoof in Chrome For iOS | $500 | 2016-10-02 |
494640 | Security: Universal XSS using IDBKeyRange static methods | $7,500 | 2016-10-02 |
494043 | ASSERTION FAILED: !node || (node->isContainerNode()) | - | 2016-10-02 |
495934 | Security: Unicode "Lock" character ( | - | 2016-10-02 |
492981 | Heap-use-after-free in blink::HTMLFormElement::item | - | 2016-10-02 |
493243 | Heap-use-after-free in blink::Frame::deprecatedLocalOwner | $2,000 | 2016-10-02 |
493935 | Distinguish file: origins by hostname AND pathname, just not pathname | - | 2016-10-02 |
492448 | Security: Update NSS to 3.19 | - | 2016-10-02 |
492490 | ASSERTION FAILED: offset + length <= m_length | - | 2016-10-02 |
492634 | Security: Information for reporting Canary build bugs sends you to an insecure webpage | - | 2016-10-02 |
492263 | UNKNOWN in SkSweepGradient::SweepGradientContext::shadeSpan | $5,000 | 2016-10-02 |
492052 | Security: libexpat buffer-overflow seems to affect latest version of chromium on Linux x86_64 | $500 | 2016-10-02 |
491975 | Heap-buffer-overflow in SI8_opaque_D32_nofilter_DX | $1,000 | 2016-10-02 |
491742 | UNKNOWN in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
492265 | Heap-use-after-free in SkCreateBitmapShader | $1,000 | 2016-10-02 |
491660 | Heap-buffer-overflow in convolve4RowsHorizontally_SSE2 | $5,000 | 2016-10-02 |
491584 | Use-of-uninitialized-value in media::VideoFrameCompositor::GetCurrentFrameAndUpdateIfStale | - | 2016-10-02 |
491582 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
491216 | Make IOBuffer, IOBufferWithSize and ShrinkableIOBufferWithSize resilient against truncation. | - | 2016-10-02 |
490721 | Heap-buffer-overflow in blink::CSSSelector::matchNth | - | 2016-10-02 |
490722 | Heap-use-after-free in blink::LayoutMultiColumnSet::flowThreadTranslationAtOffset | - | 2016-10-02 |
490506 | UNKNOWN in v8::internal::CompilationDependencies::Abort | - | 2016-10-02 |
490505 | Heap-use-after-free in blink::AXObject::document | - | 2016-10-02 |
490496 | Heap-use-after-free in plugins::LoadablePluginPlaceholder::DidFinishLoadingCallback | - | 2016-10-02 |
490492 | Security: heap-use-after-free in WebsiteSettingsInfoBarDelegate::Create | $1,000 | 2016-10-02 |
505614 | Use-of-uninitialized-value in std::__1::__tree<content::WebContents*, std::__1::less<content::WebContents*>, s | - | 2016-10-02 |
505374 | UNKNOWN in blink::EventTarget::getEventListeners | $1,000 | 2016-10-02 |
505341 | UNKNOWN in v8::internal::ScopeIterator::Type | - | 2016-10-02 |
505227 | Use-of-uninitialized-value in GrAAConvexTessellator::addTri | - | 2016-10-02 |
504691 | Heap-buffer-overflow in content::NavigationControllerImpl::RendererDidNavigateToExistingPage | - | 2016-10-02 |
504688 | Heap-use-after-free READ 8 in blink::DeprecatedPaintLayer::mapRectToPaintBackingCoordinates | - | 2016-10-02 |
504727 | UNKNOWN in v8::internal::Object::GetProperty | - | 2016-10-02 |
504692 | Heap-use-after-free in views::internal::NativeWidgetPrivate::GetNativeWidgetForNativeView | - | 2016-10-02 |
504687 | Use-of-uninitialized-value in SkCanvas::concat | - | 2016-10-02 |
504690 | Use-of-uninitialized-value in blink::encodePixels | - | 2016-10-02 |
504685 | Heap-use-after-free in blink::WorkerScriptLoader::loadAsynchronously | - | 2016-10-02 |
503217 | Security: improperly escaped "saved from url" info allows modification of saved pages | $500 | 2016-10-02 |
502863 | Use-after-poison in blink::HTMLMediaElement::setReadyState | - | 2016-10-02 |
502859 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
502794 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | - | 2016-10-02 |
502793 | Heap-use-after-free in blink::Touch::Touch | - | 2016-10-02 |
502792 | Stack-buffer-overflow in FixWinding | - | 2016-10-02 |
502858 | Heap-use-after-free in blink::SuspendableScriptExecutor::contextDestroyed | - | 2016-10-02 |
501973 | Heap-double-free in gfxReleaseSharedStateAndHash | - | 2016-10-02 |
501891 | Bad-cast to blink::EventTarget from blink::MediaDevices;ScriptWrappable.h:67:16 | - | 2016-10-02 |
501888 | Heap-use-after-free in blink::ScreenOrientationController::dispatchChangeEvent | - | 2016-10-02 |
502562 | Heap-use-after-free in WebLocalFrameImpl::printBegin | $3,000 | 2016-10-02 |
501889 | Heap-buffer-overflow in CPDF_ICCBasedCS::GetDefaultValue | - | 2016-10-02 |
500877 | Security: XSSAuditor bypass with leading regexp inside svg script tag. | - | 2016-10-02 |
501428 | Stack-use-after-return in blink::DisplayItemClientWrapper::displayItemClient | - | 2016-10-02 |
501113 | Vulnerability reported in dev-libs/openssl | - | 2016-10-02 |
500026 | Security: Non-temporal store row-hammer vulnerability | - | 2016-10-02 |
499789 | Heap-use-after-free in v8::internal::JSTypedArray::MaterializeArrayBuffer | - | 2016-10-02 |
500355 | Heap-use-after-free in v8::HandleScope::Initialize | - | 2016-10-02 |
500175 | Heap-buffer-overflow in v8::internal::JSTypedArray::MaterializeArrayBuffer | - | 2016-10-02 |
500352 | Use-after-poison in blink::HTMLMediaElement::~HTMLMediaElement | - | 2016-10-02 |
499279 | Web MIDI performance crashes chrome canary | $2,000 | 2016-10-02 |
499465 | Security: WebKit ASLR is consistent across renderers | - | 2016-10-02 |
512445 | Heap-use-after-free in in CPDFSDK_PageView::GetAnnotByDict | - | 2016-10-02 |
511554 | Vulnerability reported in net-misc/curl-7.23.1-r1 | - | 2016-10-02 |
511616 | Security: Performance APIs reveal cross-origin URLs. | $1,000 | 2016-10-02 |
511553 | Vulnerability reported in dev-libs/openssl-1.0.1c-r9 | - | 2016-10-02 |
509775 | Remove unused jump_elimination_allowed parameter to Assembler::branch_offset() | - | 2016-10-02 |
510702 | Heap-use-after-free in blink::CompositorWorkerManager::shutdown | - | 2016-10-02 |
510707 | Heap-use-after-free in blink::Font::buildTextBlob | - | 2016-10-02 |
510802 | Security: webRequest API allows intercepting XHR from apps and extensions | $3,000 | 2016-10-02 |
510850 | Security: Chrome inadvertently includes a supercookie via DTLS cert information | - | 2016-10-02 |
509666 | Security: ARM constant pool can be blocked for too long | - | 2016-10-02 |
509463 | ASSERTION FAILED: !object || (object->isLayoutMultiColumnSet()) | - | 2016-10-02 |
509461 | Heap-use-after-free in blink::Node::insertBefore | - | 2016-10-02 |
509458 | Heap-use-after-free in v8::internal::MemoryReducer::TimerTask::Run | $3,500 | 2016-10-02 |
509670 | MIPS trampoline pool emission seems to be wrong sometimes | - | 2016-10-02 |
509313 | chrome.embeddedSearch.newTabPage.navigateContentWindow is too powerful | $1,000 | 2016-10-02 |
508792 | Uninit read from cc::LayerTreeHostImpl::LayerTreeHostImpl | - | 2016-10-02 |
508705 | Use-of-uninitialized-value in blink::MediaQueryExp::createIfValid | - | 2016-10-02 |
508703 | Use-of-uninitialized-value in AAFillRectBatch::onCombineIfPossible | - | 2016-10-02 |
508540 | Unicode-decoder: fix out-of-band write in utf16 | - | 2016-10-02 |
508086 | Security: Flash UAF with Color.setTransform in AS2 | - | 2016-10-02 |
508983 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
508979 | Heap-use-after-free in blink::DeprecatedPaintLayer::setGroupedMapping | - | 2016-10-02 |
508876 | GetStringUTFChars() no longer returns Modified UTF-8 in Android M | - | 2016-10-02 |
508872 | Merge out-of-bounds accesses found by WebRTC fuzzing. | - | 2016-10-02 |
507990 | Use-after-free in blink::V8Window::namedPropertyGetterCustom | - | 2016-10-02 |
507988 | Heap-use-after-free in blink::DeprecatedPaintLayer::setGroupedMapping | $3,500 | 2016-10-02 |
507821 | Send SafeBrowsing ping-backs for additional file types | - | 2016-10-02 |
508072 | Security: Flash Heap-use-after-free in SurfaceFilterList::CĂąÂÂreateFromScriptAtom. Alwayzzzzzzz | $7,500 | 2016-10-02 |
507020 | Use-after-free in blink::AXNodeObject::document | - | 2016-10-02 |
507018 | Use-of-uninitialized-value in Browser::GetSecurityStyle | - | 2016-10-02 |
508009 | Security: Flash Use After Free in TextLine.opaqueBackground | - | 2016-10-02 |
507992 | Heap-use-after-free in blink::DeprecatedPaintLayer::updatePagination | - | 2016-10-02 |
507272 | Potential Flash 0-day Exploit ('flash-0day-vitaly1') | - | 2016-10-02 |
506749 | Heap-use-after-free in crypto::Encryptor::Decrypt | - | 2016-10-02 |
507017 | Use-of-uninitialized-value in blink::GraphicsContext::realizePaintSave | - | 2016-10-02 |
506763 | stack-use-after-return in opj_pi_next_rpcl | $500 | 2016-10-02 |
506540 | UNKNOWN in v8::internal::Simulator::InstructionDecode | - | 2016-10-02 |
505829 | Byte Serving Information Leak | - | 2016-10-02 |
516365 | Heap-use-after-free in media::DecryptingDemuxerStream::~DecryptingDemuxerStream | - | 2016-10-02 |
516298 | Many media/track/ layout tests flakily crash | - | 2016-10-02 |
516266 | Stack-buffer-overflow in SkIntersections::removeOne | $3,000 | 2016-10-02 |
516361 | Heap-buffer-overflow in gfx::FindValidBoundaryBefore | - | 2016-10-02 |
516690 | Security: WebUI backends inject data into random web pages (tracking bug) | - | 2016-10-02 |
514758 | Use-of-uninitialized-value in SkUnPreMultiply::UnPreMultiplyPreservingByteOrder | - | 2016-10-02 |
514756 | Use-of-uninitialized-value in SuperBlitter::blitH | - | 2016-10-02 |
516088 | Heap-buffer-overflow in content::NavigationControllerImpl::InsertOrReplaceEntry | - | 2016-10-02 |
514891 | Heap-buffer-overflow in CJBig2_Context::parseSymbolDict | $2,000 | 2016-10-02 |
514759 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
514080 | !field_type->NowStable() || field_type->NowContains(value) in src/objects-debug. | - | 2016-10-02 |
514076 | Security: localStorage of file:// can be read from any remote origin through a blob: document with the origin of null | $1,000 | 2016-10-02 |
514122 | UNKNOWN in v8::internal::MemoryChunk::IsFlagSet | - | 2016-10-02 |
514755 | Heap-use-after-free in blink::ComposedTreeTraversal::traverseParent | - | 2016-10-02 |
514753 | Use-of-uninitialized-value in blink::Font::glyphDataForCharacter | - | 2016-10-02 |
513917 | Heap-use-after-free in ui::InputMethodAuraLinux::ResetContext | - | 2016-10-02 |
513602 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
512678 | Security: CSS font loading API bypasses CORS | $500 | 2016-10-02 |
526286 | Container-overflow in blink::HTMLTreeBuilder::processStartTagForInBody | - | 2016-10-02 |
526441 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
526378 | Security: Pointerlock browser UI hijack | - | 2016-10-02 |
526025 | SEGV in SkOpSpan::containsCoincidence | - | 2016-10-02 |
526244 | Attempting free in v8::internal::Heap::FreeDeadArrayBuffersHelper | - | 2016-10-02 |
525696 | ASSERTION FAILED: !containsWrapper() | - | 2016-10-02 |
525330 | Null out DOMWindow::m_frame as soon as the frame/window is detached | - | 2016-10-02 |
524899 | Adobe Flash Player AdBreakTimelineItem class Memory Corruption Vulnerability | $3,000 | 2016-10-02 |
525832 | chromewebdata intermediary page can throw a Javascript syntax error | - | 2016-10-02 |
525763 | Heap-buffer-overflow in SkCreateBitmapShader | - | 2016-10-02 |
524096 | Use-of-uninitialized-value from GpuCommandBufferStub::OnInitializeFailed() | - | 2016-10-02 |
524094 | Use-of-uninitialized-value in GrTextureDomain::GLDomain::setData | - | 2016-10-02 |
524694 | Heap-use-after-free in blink::FrameLoaderClientImpl::dispatchDidFinishDocumentLoad | - | 2016-10-02 |
524682 | Bad-cast to blink::LayoutText from blink::LayoutBlockFlow;LayoutText.h:237:1 | - | 2016-10-02 |
524074 | Security: Universal XSS by loading a javascript: URI from an unloaded window | $7,500 | 2016-10-02 |
522791 | Security: Universal XSS using navigator.serviceWorker.ready | $7,500 | 2016-10-02 |
523453 | UNKNOWN in v8::internal::Deserializer::FlushICacheForNewCodeObjects | - | 2016-10-02 |
522128 | Security: Blink passes NULL TypedArray backing stores to V8, leading to OOB R/W | - | 2016-10-02 |
521655 | window.find() with unusual HTML fails to handle shadow tree | - | 2016-10-02 |
522131 | UNKNOWN in _CMapLookupCallback | $3,000 | 2016-10-02 |
521588 | Security: leaking previous webpage through webGL canvas preserveDrawingbuffer and scissor. | - | 2016-10-02 |
519558 | Security: Universal XSS via ContainerNode::parserInsertBefore | $8,837 | 2016-10-02 |
520422 | Security: Cross-site read access to PDF files | $4,000 | 2016-10-02 |
520792 | Heap-use-after-free in blink::DocumentLoader::dataReceived | - | 2016-10-02 |
521343 | Popunder is possible again (seemingly using Flash) | - | 2016-10-02 |
519642 | Security: Memory-safety bug in Image11::map | $1,000 | 2016-10-02 |
518827 | Security: chrome.runtime.setUninstallURL does not validate its URL parameter | $3,000 | 2016-10-02 |
517906 | Security: Installed extensions can read memory mapping information. | - | 2016-10-02 |
517854 | Global-buffer-overflow in FXSYS_itoa | - | 2016-10-02 |
518749 | Security: Heap-use-after-free in UsbContext::UsbEventHandler::Stop | $3,000 | 2016-10-02 |
518206 | Security: Overflow in VertexBufferInterface::reserveVertexSpace causes memory-safety bug | $5,000 | 2016-10-02 |
517913 | ASSERTION FAILED: it != m_scriptsToExecuteInOrder.end() | - | 2016-10-02 |
516821 | latest Chrome Canary(syzyasan) crashes constantly when querying crbug.com | - | 2016-10-02 |
517383 | Adobe Flash Player Regular Expression Out-Of-Bounds Write Remote Code Execution Vulnerability | $3,000 | 2016-10-02 |
534621 | Update FreeType with a recent series of patches | - | 2016-10-02 |
534570 | CSP: wildcard source expression (*) should not match data URIs | $500 | 2016-10-02 |
534542 | CSP: `*.x.y` must match a host that ends with `.x.y` (4.2.2 step 4.6) | $500 | 2016-10-02 |
532967 | UNKNOWN in vp8_read_mv_component | $500 | 2016-10-02 |
533778 | Security: Changing URL from your website to any other that uses HTTP BASIC AUTHENTICATION. | - | 2016-10-02 |
533520 | Security: Links to "file://" URLs in PDFs | - | 2016-10-02 |
532758 | Vulnerability reported in libpng | - | 2016-10-02 |
532450 | Vulnerability reported in sys-kernel/chromeos-kernel-3_10 | - | 2016-10-02 |
532448 | Vulnerability reported in sys-kernel/chromeos-kernel-3_10 | - | 2016-10-02 |
532762 | Vulnerability reported in libevent | - | 2016-10-02 |
532449 | Vulnerability reported in sys-kernel/chromeos-kernel-3_10 | - | 2016-10-02 |
531891 | Security: Universal XSS using exceptions thrown from Object.observe | $7,500 | 2016-10-02 |
532439 | Vulnerability reported in sys-kernel/chromeos-kernel-3_8 | - | 2016-10-02 |
532440 | Vulnerability reported in sys-kernel/chromeos-kernel-3_8 | - | 2016-10-02 |
531057 | Bad-cast to blink::ScriptWrappable from blink::WorkerWebSocketChannel;DOMWrapperMap.h:148:20 | $3,500 | 2016-10-02 |
530301 | Security: Universal XSS using stack overflow exceptions | $7,500 | 2016-10-02 |
529682 | Content script is able to eval code in background page of other extension | $3,000 | 2016-10-02 |
531664 | CFI: invalid cast in list_container.h | - | 2016-10-02 |
529530 | Heap-use-after-free in blink::DateTimeChooserImpl::didClosePopup | - | 2016-10-02 |
529527 | Use-of-uninitialized-value in content::EchoInformation::UpdateAecDelayStats | - | 2016-10-02 |
529520 | Heap-use-after-free in content::EmbeddedWorkerInstance::ReleaseProcess | $3,500 | 2016-10-02 |
529489 | Security: Tracking bug for upstream NSS issues | - | 2016-10-02 |
529310 | Bad-cast to CJS_EventHandler from ;PublicMethods.cpp:2026:7 | - | 2016-10-02 |
529552 | Heap-buffer-overflow in UpdateDelayMetrics | - | 2016-10-02 |
529531 | Heap-use-after-free in blink::WebViewImpl::close | - | 2016-10-02 |
529012 | Bad-cast to util from Document;JS_Define.h:165:13 | $3,500 | 2016-10-02 |
528798 | Bad-cast to blink::ScriptWrappable from blink::WebGLRenderingContextBase::TypedExtensionTracker<blink::ANGLEInstancedArrays>;ScriptWrappable.h:192:32 | - | 2016-10-02 |
528505 | Security: Linking to chrome:// urls inside pdf | $4,000 | 2016-10-02 |
528799 | Bad-cast to icu_54::UnicodeSet from icu_54::Quantifier;rbt_pars.cpp:1105:22 | - | 2016-10-02 |
528628 | Heap-buffer-overflow in C:\clusterfuzz\slave-bot\builds\chrome-test-builds_media_win32-release_e999b7478 | - | 2016-10-02 |
527466 | Security: Linux x86_64 vsyscall provides attack vectors | - | 2016-10-02 |
527514 | Security: SAN-01-001 Angular ngSanitize bypass using SVG <use> & insecure JSON Callback in Blink | - | 2016-10-02 |
527423 | Security: Integer overflow in open-vcdiff results in OOB read in browser process | - | 2016-10-02 |
545173 | Security: UAF in CPWL_ComboBox::OnKeyDown in PDFium | - | 2016-10-02 |
544765 | Privacy: browser history sniffing attack using HSTS + CSP | $500 | 2016-10-02 |
544691 | Use-of-uninitialized-value in blink::encodePixels | $2,000 | 2016-10-02 |
544020 | Security: blink::WeekInputType uaf vulnerability | $3,000 | 2016-10-02 |
543994 | Crash in NULL@0x...60 | - | 2016-10-02 |
543528 | Heap-use-after-free in v8::internal::compiler::DeadCodeElimination::ReduceLoopOrMerge | - | 2016-10-02 |
544270 | Update harfbuzz to 1.0.6 | - | 2016-10-02 |
542054 | Security: properly escaped href attribute leading to offline XSS upon saving a page | $500 | 2016-10-02 |
541669 | Security: Security: signed integer overflow in media/formats/mp2t/es_parser_h264.cc | - | 2016-10-02 |
541594 | Bad-cast to v8::String::ExternalStringResource from invalid vptr;objects-inl.h:4047:10 | - | 2016-10-02 |
541593 | Heap-buffer-overflow in blink::SVGFilterGraphNodeMap::addPrimitive | $1,500 | 2016-10-02 |
542060 | CSP for Evil & Service Workers | - | 2016-10-02 |
541323 | Heap-buffer-overflow in CJBig2_HuffmanTable::parseFromCodedBuffer | - | 2016-10-02 |
541322 | Bad-cast to blink::WebTaskRunner from invalid vptr;BackgroundHTMLParser.cpp:109:36 | - | 2016-10-02 |
540949 | Security: Webpage can bypass arbitrary interstitial using HTTP auth dialog | - | 2016-10-02 |
539908 | Heap-use-after-free in blink::RejectedPromises::processQueueNow | - | 2016-10-02 |
539875 | Security: Symbols ignored in Object.{freeze, seal, isFrozen, isSealed}() | - | 2016-10-02 |
539691 | Heap-buffer-overflow in SkBlitter::blitMask | - | 2016-10-02 |
541415 | Security: URL Spoofing when victim tries to access another website from attacker's page. | $500 | 2016-10-02 |
541206 | Security: Universal XSS using document.adoptNode | $7,500 | 2016-10-02 |
539563 | Heap-buffer-overflow in net::HpackEncoder::EncodeHeaderSet | - | 2016-10-02 |
538952 | Bad-cast to Profile from invalid vptr;chrome_extensions_network_delegate.cc:38:22 | - | 2016-10-02 |
537666 | Remove references to unloadEvent in runtime_custom_bindings.js | - | 2016-10-02 |
538256 | Heap-use-after-free in blink::FrameLoaderClientImpl::dispatchDidFinishDocumentLoad | - | 2016-10-02 |
538257 | Crash in v8::internal::FlexibleBodyVisitor<v8::internal::MarkCompactMarkingVisitor,v8::in | - | 2016-10-02 |
537823 | Security: The password manager can be tricked to put one site's saved credential's into another's with HTTP auth | - | 2016-10-02 |
537205 | Security: Crazy Linker on Android allows modification of Chrome APK without breaking signature | $1,000 | 2016-10-02 |
536917 | Heap-use-after-free in blink::RadioInputType::didDispatchClick | - | 2016-10-02 |
537656 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
537173 | Security: PureCall on CPWL_Edit::OnKillFocus | $3,000 | 2016-10-02 |
537660 | Remove stash_client.js dependency on unload_event | - | 2016-10-02 |
537658 | Remove extension dependencies on unload_event.js | - | 2016-10-02 |
536601 | Crash in ff_sbr_hf_apply_noise_3_sse2 | - | 2016-10-02 |
536231 | Heap-double-free in v8::internal::ArrayBufferTracker::FreeDead | - | 2016-10-02 |
535605 | heap-use-after-free in AudioOutputDevice | - | 2016-10-02 |
536701 | Chrome mobile for iOS thinks JavaScript redirects are a form of certificate spoofing of trusted domains | $500 | 2016-10-02 |
536652 | Security: Disrupting the omnibox from the attacker's website. | $1,000 | 2016-10-02 |
536640 | Heap-use-after-free in blink::InlineTextBox::selectionState | - | 2016-10-02 |
534994 | Heap-use-after-free in extensions::BookmarkAppHelper::OnBubbleCompleted | - | 2016-10-02 |
534923 | Security: Universal XSS via the unload_event module | $7,500 | 2016-10-02 |
534992 | Heap-use-after-free in blink::TimerBase::stop | - | 2016-10-02 |
534993 | Heap-use-after-free in blink::CSSImageSetValue::valueWithURLsMadeAbsolute | - | 2016-10-02 |
555784 | Heap-buffer-overflow in CCodec_RLScanlineDecoder::v_GetNextLine | - | 2016-10-02 |
555575 | Heap-use-after-free in webrtc::PeerConnection::OnSessionStateChange | - | 2016-10-02 |
555544 | crash in SkSweepGradient::SweepGradientContext::shadeSpan | $2,000 | 2016-10-02 |
554648 | Factory reset can be performed when it should be disallowed. | - | 2016-10-02 |
554172 | Heap-buffer-overflow in opj_jp2_apply_pclr | - | 2016-10-02 |
554151 | Heap-buffer-overflow in CPDF_DIBSource::DownSampleScanline32Bit | - | 2016-10-02 |
554129 | Heap-buffer-overflow in opj_j2k_read_mcc | - | 2016-10-02 |
554115 | Heap-buffer-overflow in CPDF_TextObject::CalcPositionData | - | 2016-10-02 |
554946 | Security: Pwn2Own mobile case, out-of-bound access in json stringifier | $7,500 | 2016-10-02 |
554908 | Security: AppCacheDispatcherHost UaF with host transfer | $10,000 | 2016-10-02 |
554099 | Crash in v8::internal::StaticMarkingVisitor<v8::internal::IncrementalMarkingMarkingVisito | - | 2016-10-02 |
553050 | Heap-use-after-free in blink::PartPainter::isSelected | - | 2016-10-02 |
553054 | Heap-use-after-free in blink::V8SVGMatrix::visitDOMWrapper | - | 2016-10-02 |
552870 | ASSERTION FAILED: index < arraySize | - | 2016-10-02 |
553049 | Use-of-uninitialized-value in blink::LayoutObject::findNextLayer | - | 2016-10-02 |
552749 | window.crypto.getRandomValues() uses a weak CSPRNG | $500 | 2016-10-02 |
553048 | Heap-use-after-free in blink::LayoutBlock::removeChild | $3,500 | 2016-10-02 |
552448 | Security: PDFium: XFA: UAF in CXFA_PDFFontMgr::~CXFA_PDFFontMgr() | - | 2016-10-02 |
552046 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
551503 | Heap-buffer-overflow in cff_get_glyph_name | - | 2016-10-02 |
551470 | Heap-buffer-overflow in opj_t2_read_packet_header | - | 2016-10-02 |
551460 | Stack-buffer-overflow in CPDF_Function::Call | - | 2016-10-02 |
551116 | chrome crash during dark resume leaves zombie processes, reparented to init, which makes new chrome instance unusable. | - | 2016-10-02 |
551044 | Security: AppCacheUpdateJob accesses map::end() | $11,337 | 2016-10-02 |
551028 | FreeType : pick up post-2.6.1 patches (or 2.6.2 when it's out) | - | 2016-10-02 |
550972 | Security: app_mode_loader not signed on OSX | - | 2016-10-02 |
551288 | Crash in v8::internal::Heap::DoScavenge | - | 2016-10-02 |
550629 | Heap-use-after-free in content::RenderMessageFilter::OnKeygen | - | 2016-10-02 |
551143 | Heap-use-after-free in content::BindWebGraphicsContext3DGLContextCallback | - | 2016-10-02 |
550632 | Use-after-poison in blink::WorkerWebSocketChannel::Bridge::traceImpl<blink::InlinedGlobalMarkingVisi | $3,500 | 2016-10-02 |
549155 | Use-of-uninitialized-value in filter8 | - | 2016-10-02 |
550047 | Security: Inline extension installation dialog doesn't block and persists after redirect | $1,000 | 2016-10-02 |
546849 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
546848 | ASSERTION FAILED: !m_pendingInOrderScripts.isEmpty() | - | 2016-10-02 |
546846 | Heap-use-after-free in views::NativeWidgetAura::ShouldDescendIntoChildForEventHandling | - | 2016-10-02 |
546545 | Security: Universal XSS using plugin objects | $7,500 | 2016-10-02 |
545520 | Heap-buffer-overflow in blink::MarkupFormatter::appendCharactersReplacingEntities | - | 2016-10-02 |
567688 | Vulnerability reported in dev-libs/openssl | - | 2016-10-02 |
567445 | Security: URL Spoofing with HTTPS lock | $1,000 | 2016-10-02 |
566156 | Security: QUIC may send requests (including cookies) in the clear | - | 2016-10-02 |
566142 | Heap-use-after-free in blink::WebLocalFrameImpl::didFail | - | 2016-10-02 |
566231 | Security: chromeos-base/chromeos-ca-certificates is out of date | - | 2016-10-02 |
565760 | Security: Drop-downs hiding any part of the browser UI, allowing for several types of spoof attacks | $3,133 | 2016-10-02 |
565543 | Privileged installer directory is writeable by lower privileged users | - | 2016-10-02 |
565967 | Heap-use-after-free in webrtc::VCMGenericDecoder::Release | - | 2016-10-02 |
565416 | Security: OpenSSL 1.0.2e fixes | - | 2016-10-02 |
565048 | Heap-use-after-free in webrtc::DataChannel::UpdateState | - | 2016-10-02 |
565046 | Crash in v8::internal::RootMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
565023 | Security: Google Chrome: Privilege Escalation from Renderer Process to Browser Process | - | 2016-10-02 |
564501 | Security: UAF in MidiHost (Sandbox escape) | - | 2016-10-02 |
564238 | Security: Windows Image Sections Allow Mapping Arbitrary Executable Memory into More Privileged Processes | - | 2016-10-02 |
563964 | Security: GPU process to privileged renderer IPC bug? | - | 2016-10-02 |
565049 | Heap-use-after-free in blink::FrameSelection::notifyLayoutObjectOfSelectionChange | - | 2016-10-02 |
562986 | Heap-use-after-free in blink::FrameLoader::init | - | 2016-10-02 |
562984 | Use-of-uninitialized-value in blink::CachingWordShapeIterator::nextWord | - | 2016-10-02 |
561972 | Crash in v8::internal::HeapObject::VerifyHeapPointer | - | 2016-10-02 |
563688 | Security: Code Review Clickjacking | - | 2016-10-02 |
562208 | Heap-use-after-free in blink::LayoutBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
561497 | Heap-use-after-free in content::VideoCaptureController::RemoveClient | - | 2016-10-02 |
561505 | Global-buffer-overflow in blink::getPropertyName | - | 2016-10-02 |
561869 | Bad-cast to blink::StaticBitmapImage from blink::BitmapImage;ImageBitmap.cpp:51:25 | - | 2016-10-02 |
561488 | Heap-buffer-overflow in blink::appendCharactersReplacingEntitiesInternal<unsigned char const > | - | 2016-10-02 |
561478 | Heap-use-after-free in FT_Stream_ReleaseFrame | - | 2016-10-02 |
560480 | Global-buffer-overflow in blink::getPropertyName | - | 2016-10-02 |
560291 | Security: security vulnerabilities in libpng (CVE-2015-7981, CVE-2015-8126) | $500 | 2016-10-02 |
561492 | Heap-use-after-free in blink::PlatformEventDispatcher::notifyControllers | - | 2016-10-02 |
559528 | Heap-use-after-free in blink::LayoutTextFragment::setTextFragment | - | 2016-10-02 |
559515 | Security: Bypass to Multiple Files dialog allows for system crash or disk exhaustion | - | 2016-10-02 |
560011 | Security: Universal XSS using widget updates in ContainerNode::parserRemoveChild | $8,000 | 2016-10-02 |
559292 | Security: heap-use-after-free in blink::ScopedStyleResolver::collectMatchingAuthorRules | $3,000 | 2016-10-02 |
559075 | Vulnerability reported in net-misc/strongswan | - | 2016-10-02 |
559541 | Flash: Uninitialized variable in DateObject::_toString can cause memory corruption | $5,000 | 2016-10-02 |
559310 | Security: SharedWorkerDevToolsAgentHost UAF (sandbox escape) | - | 2016-10-02 |
558589 | Security: AppCacheUpdateJob UaF | $10,000 | 2016-10-02 |
557981 | Security: heap-use-after-free in blink::MutationObserver::enqueueMutationRecord | $2,000 | 2016-10-02 |
557806 | Heap-use-after-free: text-transform CSS property breaks document life time cycle | - | 2016-10-02 |
557802 | Bad-cast to blink::HTMLOptionElement from blink::HTMLOptGroupElement;Element.h:704:12 | - | 2016-10-02 |
558840 | Crash in NULL@0x...40 | - | 2016-10-02 |
557799 | Crash in Init | - | 2016-10-02 |
557797 | Heap-use-after-free in I422ToARGBRow_Any_SSSE3 | - | 2016-10-02 |
557223 | Pdfium heap-buffer-overflow in sycc422_to_rgb | $500 | 2016-10-02 |
556725 | Investigate legality of call to ContextGL in RenderThreadImpl::SharedWorkerContextProvider | - | 2016-10-02 |
556724 | Security: Universal XSS via persistence of subframes | $8,000 | 2016-10-02 |
557800 | Heap-use-after-free in autofill::FormStructure::ParseQueryResponse | - | 2016-10-02 |
556351 | Crash in password_manager::ContentPasswordManagerDriver::OnPasswordFormsParsed | - | 2016-10-02 |
556584 | Heap-use-after-free in content::MemoryMessageFilter::OnChannelClosing | - | 2016-10-02 |
574802 | ASSERTION FAILED: index < arraySize | $3,000 | 2016-10-02 |
574114 | Use-of-uninitialized-value in S32A_Opaque_BlitRow32_SSE4 | $1,000 | 2016-10-02 |
573332 | Heap-buffer-overflow in xmlParseXMLDecl | - | 2016-10-02 |
573317 | UX and Extensions API confusion when file: URLs have hostnames | $500 | 2016-10-02 |
573284 | Heap-buffer-overflow in blink::TimerBase::stop | $3,500 | 2016-10-02 |
573281 | Heap-use-after-free in blink::InlineWalker::InlineWalker | - | 2016-10-02 |
572871 | Security: PureCall on CPWL_Edit::OnKillFocus | $3,000 | 2016-10-02 |
573886 | Heap-use-after-free in extensions::MimeHandlerViewContainer::DidFinishLoading | - | 2016-10-02 |
572409 | Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer | - | 2016-10-02 |
572408 | Use-of-uninitialized-value in v8::internal::compiler::VirtualState::MergeFrom | - | 2016-10-02 |
572407 | Heap-use-after-free in blink::Node::assignedSlot | - | 2016-10-02 |
572406 | Use-of-uninitialized-value in winding_mono_conic | - | 2016-10-02 |
572404 | Heap-use-after-free in ash::WindowSelector::ContentsChanged | $1,000 | 2016-10-02 |
572537 | Security: heap-use-after-free in blink::NodeIteratorBase::root | $3,000 | 2016-10-02 |
572403 | Heap-buffer-overflow in SkARGB32_Opaque_Blitter::blitAntiH2 | - | 2016-10-02 |
572398 | Heap-use-after-free in content::WebMediaPlayerMSCompositor::StopRenderingInternal | - | 2016-10-02 |
572224 | UNKNOWN in extensions::WebrtcAudioPrivateFunction::CalculateHMACImpl | $1,000 | 2016-10-02 |
571480 | ZDI-CAN-3447: New Vulnerability Report Google Chrome Pdfium JPEG2000 Out-Of-Bounds Read Remote Code Execution Vulnerability | - | 2016-10-02 |
571479 | ZDI-CAN-3432: New Vulnerability Report | - | 2016-10-02 |
571121 | Security: Devtools loads any URL with remoteBase parameter | - | 2016-10-02 |
571617 | Security: dev-tools: URIs can be copy&paste'd | - | 2016-10-02 |
570750 | Security: Android Chrome download files into arbitrary sdcard directory | $500 | 2016-10-02 |
570618 | Vulnerability reported in dev-libs/libxml2 | - | 2016-10-02 |
570561 | Bad-cast to const blink::LayoutBox from blink::LayoutInline;LayoutBox.h:1001:1 | - | 2016-10-02 |
570427 | UaF in blink::SearchInputType::didSetValueByUserEdit | - | 2016-10-02 |
570262 | Crash in v8::internal::Invoke | - | 2016-10-02 |
571119 | Security: Extensions can open privileged URLs using tabs URL | - | 2016-10-02 |
570261 | Heap-buffer-overflow in sctp_setopt | - | 2016-10-02 |
570255 | Heap-buffer-overflow: LayoutObject should have height even if it is placed very far place | - | 2016-10-02 |
570241 | Stack-buffer-underflow in v8::internal::QuickCheckDetails::Advance | - | 2016-10-02 |
569956 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
569940 | Stack-buffer-underflow in v8::internal::Trace::AdvanceCurrentPositionInTrace | - | 2016-10-02 |
569496 | Security: Universal XSS using Flash message loop | $7,500 | 2016-10-02 |
569420 | Heap-use-after-free in cricket::ChannelManager::RemoveVideoRenderer | - | 2016-10-02 |
569170 | Heap-use-after-free in blink::ColorInputType::didChooseColor | - | 2016-10-02 |
569043 | onmouseenter/leave + ES6 on window leaks functions between origins | - | 2016-10-02 |
568889 | Stack-buffer-overflow in WebRtcIlbcfix_CreateAugmentedVec | - | 2016-10-02 |
568885 | Stack-buffer-overflow in WebRtcSpl_ElementwiseVectorMult | - | 2016-10-02 |
569284 | Heap-use-after-free in blink::Node::assignedSlot | - | 2016-10-02 |
568796 | Use-after-poison in blink::OfflineAudioContext::resolveSuspendOnMainThread | - | 2016-10-02 |
568745 | Use-of-uninitialized-value in void base::Pickle::WriteBytesStatic<4ul> | - | 2016-10-02 |
568742 | Heap-buffer-overflow in gpu::gles2::GLES2Implementation::TexImage2D | - | 2016-10-02 |
568741 | Use-of-uninitialized-value in re2::NFA::AddToThreadq | - | 2016-10-02 |
568433 | Heap-use-after-free in content::IndexedDBBackingStore::Transaction::ChainedBlobWriterImpl::ReportWriteC | $5,500 | 2016-10-02 |
567956 | adobe.com is (incorrectly) reporting out of date Flash plugin | - | 2016-10-02 |
568797 | Heap-use-after-free in content::RenderWidgetHostImpl::ScheduleComposite | - | 2016-10-02 |
568744 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
584223 | Heap-buffer-overflow in cmsDupNamedColorList | - | 2016-10-02 |
584185 | Security: Heap-use-after-free in blink::LayoutObject::parent | - | 2016-10-02 |
583563 | Heap-buffer-overflow in ConvertWOFF2ToTTF | $1,000 | 2016-10-02 |
583445 | UXSS in DocumentLoader::createWriterFor | - | 2016-10-02 |
583354 | Crash in ff_get_qtpalette | - | 2016-10-02 |
583171 | Security: Memory leak in libxslt | $1,000 | 2016-10-02 |
583156 | Security: Type confusion and UAF in libxslt | $1,000 | 2016-10-02 |
583718 | Heap-use-after-free in favicon::FaviconDriverImpl::DidDownloadFavicon | $500 | 2016-10-02 |
584155 | Security: General bypass of SRI validation for subresources located on the same origin | $2,000 | 2016-10-02 |
583607 | Security: Buffer overflow in Brotli decompression | $1,000 | 2016-10-02 |
582716 | Heap-buffer-overflow in vp9_update_noise_estimate | - | 2016-10-02 |
582721 | Use-of-uninitialized-value in SkUnPreMultiply::PMColorToColor | - | 2016-10-02 |
582713 | Use-after-poison in blink::WebGLObject::detach | - | 2016-10-02 |
583039 | Use-of-uninitialized-value in xmlCurrentChar | - | 2016-10-02 |
583041 | Use-of-uninitialized-value in xmlNextChar | - | 2016-10-02 |
582705 | Negative-size-param in SkRBufferWithSizeCheck::read | - | 2016-10-02 |
582703 | Crash in v8::internal::Runtime_FunctionGetScript | - | 2016-10-02 |
582710 | Bad-cast to blink::ContextLifecycleObserver from invalid vptr;DOMTimer.cpp:140:9 | - | 2016-10-02 |
582701 | Crash in blink::AudioParamTimeline::valuesForFrameRangeImpl | - | 2016-10-02 |
582700 | Bad-cast to blink::LayoutBox from blink::LayoutInline;LayoutBox.h:1001:1 | - | 2016-10-02 |
582699 | Crash (assert) in blink::AudioDelayDSPKernel::process | $1,500 | 2016-10-02 |
582707 | Crash in chrome | - | 2016-10-02 |
582706 | ASSERTION FAILED: !object || (object->isLayoutBlock()) | - | 2016-10-02 |
582702 | Crash in v8::internal::compiler::InstructionSequence::GetRepresentation | - | 2016-10-02 |
582695 | Heap-buffer-overflow in gpu::gles2::GLES2Implementation::TexImage2D | - | 2016-10-02 |
582480 | Use-of-uninitialized-value in icuLikeCompare | - | 2016-10-02 |
582471 | Use-of-uninitialized-value in WebRtcIsac_DecLogisticMulti2 | - | 2016-10-02 |
582470 | Use-of-uninitialized-value in icu_54::RegexCompile::doParseActions | - | 2016-10-02 |
582211 | With --site-per-process, body of POST request is not delivered to XSSAuditor | - | 2016-10-02 |
582698 | ASSERTION FAILED: !object || (object->isTableRow()) | - | 2016-10-02 |
582697 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
581905 | Use-of-uninitialized-value in xmlGROW | - | 2016-10-02 |
582008 | Heap-use-after-free when a content script synchronously removes a frame at document_start or document_end | $1,500 | 2016-10-02 |
581839 | Use-of-uninitialized-value in xmlParserPrintFileContextInternal | - | 2016-10-02 |
581836 | Use-of-uninitialized-value in xmlParseComment | - | 2016-10-02 |
581294 | Vulnerability reported in libpng | - | 2016-10-02 |
581908 | Security: Master tracking bug for chrome issue tracker libvpx fixes (January 2016) | - | 2016-10-02 |
581901 | Use-of-uninitialized-value in WebRtcIsacfix_AllpassFilter2FixDec16C | - | 2016-10-02 |
578193 | Heap-buffer-overflow in webrtc::VP9EncoderImpl::GetEncodedLayerFrame | - | 2016-10-02 |
577105 | Security: Universal XSS by circumventing the unload event | $7,500 | 2016-10-02 |
579801 | Security: CSP isn't applied to Service Workers in Chrome | $1,000 | 2016-10-02 |
577970 | ClientSideDetectionHost::OnPhishingDetectionDone never get called | - | 2016-10-02 |
580181 | Security: Reproducible tab crash when opening inspector due to DOM object corruption via marquee tag in svg | - | 2016-10-02 |
576867 | Security: Google Chrome <any version> Extensions Web Accessible Resources Bypass | $500 | 2016-10-02 |
576383 | Security: UaF in MidiHost round 2 (JS -> Browser code execution) | - | 2016-10-02 |
575220 | Heap-buffer-overflows in sqlite3 when REGEXP keyword is used | - | 2016-10-02 |
575206 | Heap-buffer-overflow in icu_54::RegexCompile::nextCharLL | - | 2016-10-02 |
575205 | Heap-buffer-overflow in icuLikeCompare (called from sqlite3_step) | - | 2016-10-02 |
576910 | Crash in SkRBufferWithSizeCheck::read | - | 2016-10-02 |
576908 | Heap-buffer-overflow in SkPaint::unflatten | - | 2016-10-02 |
590118 | Security: Universal XSS using an intercepted native function | $7,500 | 2016-10-02 |
589848 | Heap-use-after-free in FT_New_Size | $3,000 | 2016-10-02 |
589838 | Security: type confusion in blink::BaseButtonInputType::valueAttributeChanged | $5,000 | 2016-10-02 |
589792 | Security: [v8] Out of bound(??) memory write with asm.js | $5,000 | 2016-10-02 |
589512 | Use-of-uninitialized-value in ebml_read_num | $1,500 | 2016-10-02 |
589237 | Security: HTTP 302 can navigate to non-web-accessible chrome-extension:// URIs | - | 2016-10-02 |
589186 | Security: use after free in memory-only disk cache | - | 2016-10-02 |
590247 | Security: use-after-poison in blink::PersistentBase with FileSystemSync in a Shared Worker | $3,500 | 2016-10-02 |
590284 | Security: RWHI UaF from bad fullscreen widget routing id | $10,500 | 2016-10-02 |
588711 | Security: chrome canary chrome_child!blink::LayoutTableSection::layout UAF bug | - | 2016-10-02 |
588566 | Crash in blink::DocumentThreadableLoader::cancelWithError | - | 2016-10-02 |
588862 | Security: kernel CVE-2016-2384: arbitrary code execution due to a double-free in the usb-midi linux kernel driver | - | 2016-10-02 |
588552 | Heap-use-after-free in blink::DepthOrderedLayoutObjectList::ordered | - | 2016-10-02 |
588550 | Heap-use-after-free in blink::CanvasAsyncBlobCreator::createBlobAndCall | $3,500 | 2016-10-02 |
588548 | LayoutText::setTextWithOffset() should handle ::first-letter | - | 2016-10-02 |
587897 | Update libxml to 2.9.3 or latest | - | 2016-10-02 |
587852 | Use-of-uninitialized-value in WebRtcIsac_DecLogisticMulti2 | - | 2016-10-02 |
588200 | Global-buffer-overflow in XFA_FM_KeywordToString | - | 2016-10-02 |
587227 | ZDI-CAN-3563: New Vulnerability Report | - | 2016-10-02 |
586798 | Heap-use-after-free in ASN1_STRING_free | - | 2016-10-02 |
586820 | Security: Timing attack on SVG feComposite filter circumvents same-origin policy | - | 2016-10-02 |
586765 | Security: ASSERTION FAILED: obj->isLayoutInline() || obj == this in blink::LayoutBlockFlow::createLineBoxes | - | 2016-10-02 |
586800 | Use-of-uninitialized-value in lh_retrieve | - | 2016-10-02 |
586657 | Directory traversal on file:// via escaped slashes | $500 | 2016-10-02 |
586494 | Security: heap-use-after-free in blink::LayoutObject::parent | - | 2016-10-02 |
586722 | Heap-use-after-free in blink::LayoutObject::markContainerChainForPaintInvalidation | - | 2016-10-02 |
586720 | Heap-use-after-free in blink::InlineFlowBox::addToLine | $3,500 | 2016-10-02 |
586721 | Heap-use-after-free in blink::PaintArtifact::appendToWebDisplayItemList | - | 2016-10-02 |
586079 | Heap-buffer-overflow in sqlite3VdbeMemSetStr | - | 2016-10-02 |
585707 | Heap-use-after-free in media::GpuMemoryBufferVideoFramePool::PoolImpl::GetOrCreateFrameResources | - | 2016-10-02 |
585704 | Bad-cast to blink::LayoutBox from blink::LayoutInline;LayoutBox.h:1045:1 | - | 2016-10-02 |
586266 | Security: heap-use-after-free in blink::LayoutObject::LayoutObjectBitfields::selfNeedsLayout | $3,000 | 2016-10-02 |
585698 | Use-of-uninitialized-value in SkUnPreMultiply::PMColorToColor | - | 2016-10-02 |
585701 | LayoutText::previousOffsetForBackwardDeletion() should consider first-letter | - | 2016-10-02 |
585595 | Heap-use-after-free in scheduler::internal::TaskQueueImpl::GetTimeDomain | - | 2016-10-02 |
585282 | Restricted web APIs can easily be accessed from Chrome apps | $1,000 | 2016-10-02 |
585268 | Heap-use-after-free in LoadWatcher::CallbackAndDie (chrome.app.window.create) | $2,000 | 2016-10-02 |
585699 | Use-of-uninitialized-value in blink::LayoutObject::containingBlock | - | 2016-10-02 |
585658 | Security: Upstream bug reported in NSS | - | 2016-10-02 |
595656 | Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer | $3,500 | 2016-10-02 |
595836 | libANGLE buffer-overflow (part of pwn2own exploit) | - | 2016-10-02 |
595514 | Security: Navigating to "chrome://" URLs inside pdf (iOS) | $500 | 2016-10-02 |
595339 | Security: Navigating to "chrome://" URLs and "file://" URLs via window.open() | $500 | 2016-10-02 |
595262 | Heap-buffer-overflow in xmlParseEndTag2 | - | 2016-10-02 |
595259 | Crash in v8::internal::StackFrameIterator::StackFrameIterator | $3,500 | 2016-10-02 |
594958 | Crash in v8::internal::MarkCompactMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
594574 | Security: v8 Array.concat OOB access writeup | $7,500 | 2016-10-02 |
594512 | Use-of-uninitialized-value in Decode | - | 2016-10-02 |
594383 | Security: UXSS via window.open() via file:// pages | $3,000 | 2016-10-02 |
593759 | Security: Proxy Auto-Config SSL/TLS Url Disclosure | $500 | 2016-10-02 |
593690 | Use-of-uninitialized-value in xmlParseEndTag2 | - | 2016-10-02 |
594120 | Heap-use-after-free in FXJS_GetPrivate | $5,000 | 2016-10-02 |
592956 | Security: XSS on NTP | - | 2016-10-02 |
591785 | ZDI-CAN-3594: New Vulnerability Report | - | 2016-10-02 |
592361 | Use-of-uninitialized-value in v8::InstantiateModuleFromAsm | - | 2016-10-02 |
590882 | Chrome: Crash Report - gfx::Image::ToImageSkia | - | 2016-10-02 |
590801 | Use-of-uninitialized-value in blink::CSSParserToken::operator== | - | 2016-10-02 |
590620 | Heap-use-after-free in blink::FrameView::performLayout | $3,500 | 2016-10-02 |
590619 | Container-overflow in blink::HTMLMenuItemElement::defaultEventHandler | - | 2016-10-02 |
591402 | Tracking bug for internal fixes: Chrome M49, release 0 | - | 2016-10-02 |
590832 | Security: Lazy bailout from TurboFan after CompareIC is wrong | - | 2016-10-02 |
590615 | Heap-buffer-overflow in i2c_ASN1_INTEGER | - | 2016-10-02 |
590610 | Bad-cast to const blink::WebPasswordCredential from blink::WebCredential;credential_manager_content_utils.cc:26:9 | - | 2016-10-02 |
601801 | Security: Unsigned wraparound in a multiply in kbasep_vinstr_attach_client leads to a heap overflow. | - | 2016-10-02 |
601737 | content/ should destroy ImageDownloaderImpl() before shutting down Blink | - | 2016-10-02 |
601706 | Security: Universal XSS using a flaw in the load deferral logic | $7,500 | 2016-10-02 |
601629 | Security: Read access violation on same-origin, cross-process frames | $3,000 | 2016-10-02 |
601362 | Security: PDFium Out-of-Bounds Read in CFX_FaceCache::RenderGlyph | $1,000 | 2016-10-02 |
602046 | ZDI-CAN-3655: Google Chrome PDFium JPEG Out-Of-Bounds Read Information Disclosure Vulnerability | - | 2016-10-02 |
600977 | Use-of-uninitialized-value in webrtc::RTCPReceiver::HandleRPSI | - | 2016-10-02 |
601234 | Security: SDCH Get-Dictionary follows cross-domain redirects | - | 2016-10-02 |
600777 | Security: Merge bug for pdfium:419 | - | 2016-10-02 |
600735 | Heap-use-after-free in blink::LayoutObject::isAnonymousBlock | - | 2016-10-02 |
600953 | Global-buffer-overflow in WebRtcIsacfix_PitchFilterCore | - | 2016-10-02 |
600182 | Security: Universal XSS using deferred history loads | $7,500 | 2016-10-02 |
600671 | Use-of-uninitialized-value in base::Pickle::WriteData | - | 2016-10-02 |
599861 | Heap-use-after-free in blink::PaintLayer::removeChild | - | 2016-10-02 |
599855 | Use-of-uninitialized-value in blink::PaintLayerScrollableArea::invalidateAllStickyConstraints | - | 2016-10-02 |
599854 | Crash in sk_ssse3::blit_mask_d32_a8 | - | 2016-10-02 |
599849 | Heap-use-after-free in blink::LayoutBoxModelObject::invalidateStickyConstraints | $3,500 | 2016-10-02 |
599846 | Heap-buffer-overflow in media::AudioBuffer::ReadFrames | - | 2016-10-02 |
599866 | Heap-use-after-free LayoutBoxModelObject::continuation() (NO STACK) | - | 2016-10-02 |
599627 | Bad-cast to blink::LayoutBlock from blink::LayoutTableRow;LayoutBlock.h:515:1 | - | 2016-10-02 |
599625 | Heap-buffer-overflow in media::AudioBus::AudioBus | - | 2016-10-02 |
599458 | Use-of-uninitialized-value in sk_sse41::blit_row_s32a_opaque | - | 2016-10-02 |
599409 | Crash in v8::internal::Invoke | - | 2016-10-02 |
599081 | Security: GPU process BufferManager double-reads | - | 2016-10-02 |
599003 | RUNTIME_ASSERT in map->IsMap() in src/heap/spaces.cc | - | 2016-10-02 |
598848 | Crash in SkResizeFilter::computeFilters | - | 2016-10-02 |
598752 | kMainSRTDownloadURL is HTTP | $500 | 2016-10-02 |
598312 | Security: ChromeOS accepts ICMP redirects | - | 2016-10-02 |
598077 | Cross-Origin CSS Attack with Service Worker | $500 | 2016-10-02 |
598047 | Address bar not updated when returning from network error page. | - | 2016-10-02 |
597636 | Security: Possible double-reads in GPU command buffer code. | - | 2016-10-02 |
597625 | Security: GPU process MailboxManagerImpl double-reads | - | 2016-10-02 |
598165 | Security: Universal XSS via the interception of |Binding| with Object.prototype.create | $7,500 | 2016-10-02 |
597926 | Heap-buffer-overflow in SkOpContour::operand | $500 | 2016-10-02 |
597333 | CVE-2015-1805 Linux kernel: pipe: iovec overrun leading to memory corruption | - | 2016-10-02 |
596862 | Security: Block GPU Process Opening Renderer Processes | - | 2016-10-02 |
597518 | Tracking bug for internal fixes: Chrome M49, release 2 | - | 2016-10-02 |
597322 | Security: URL spoof + iframe spoof | $1,000 | 2016-10-02 |
597532 | Security: Universal XSS using a FrameNavigationDisabler bypass | $7,500 | 2016-10-02 |
606390 | Security: V8ValueConverter::ToV8Value is insecure (e.g. heap-use-after-free in MimeHandlerViewContainer::PostMessage | $3,500 | 2016-10-02 |
606185 | Heap-buffer-overflow in CopyAlphaChannelIntoVideoFrame | $1,000 | 2016-10-02 |
606181 | Security: Due to out of index of 'Node' object , attacker can control all contents of 'Node' object | $1,000 | 2016-10-02 |
606115 | Security: Use After Free in RegExp of V8 | $3,000 | 2016-10-02 |
605491 | Use-of-uninitialized-value in CPDF_TextPage::PreMarkedContent | - | 2016-10-02 |
605488 | Bad-cast to v8::internal::AstNode from invalid vptr;wasm-js.cc:138:7 | - | 2016-10-02 |
605480 | Heap-use-after-free in base::trace_event::BlameContext::Enter | - | 2016-10-02 |
605910 | Security: Universal XSS using iterables | $7,500 | 2016-10-02 |
605766 | Security: Universal XSS through adopting image elements | $8,000 | 2016-10-02 |
605470 | Crash in v8::internal::Invoke | $3,500 | 2016-10-02 |
605476 | Heap-use-after-free in extensions::ExtensionKeybindingRegistry::IsAcceleratorRegistered | - | 2016-10-02 |
604901 | Security: Persistent UXSS via SchemaRegistry | $7,500 | 2016-10-02 |
605474 | Bad-cast to net::QuicSpdySession from net::QuicSession;quic_spdy_stream.cc:41:3 | - | 2016-10-02 |
605451 | CSP 'referrer' directive ignored for preload requests | $500 | 2016-10-02 |
604897 | Compiled regexps execute incorrectly on function source strings | $1,000 | 2016-10-02 |
603748 | Security: Leak of extension privates via utils module | $1,000 | 2016-10-02 |
603725 | Security: Web pages can load arbitrary extension modules | $4,000 | 2016-10-02 |
603682 | Pinned TLS public keys (HPKP) evicted after clearing cache | $500 | 2016-10-02 |
603518 | Security: PDFium Out-of-Bounds Read in CPDF_DeviceCS::TranslateImageLine | $1,000 | 2016-10-02 |
603732 | Security: Heap-use-after-free via GCCallback | $3,000 | 2016-10-02 |
602970 | Security: type confusion lead to information leak in decodeURI | $7,500 | 2016-10-02 |
602975 | Use-of-uninitialized-value in woff2::ConvertWOFF2ToTTF | - | 2016-10-02 |
602697 | Tracking bug for internal fixes: Chrome M50, release 0 | - | 2016-10-02 |
602273 | Use-after-poison in blink::MediaStreamSource::setReadyState | - | 2016-10-02 |
602185 | Heap-buffer-overflow in fixup_vorbis_headers | - | 2016-10-02 |
602271 | Heap-use-after-free in blink::LayoutListItem::updateMarkerLocation | - | 2016-10-02 |
612364 | Security: Heap buffer overflow from unchecked length in mojo::edk::ports::Message::Parse | - | 2016-10-02 |
612132 | Security: Bypass CORS check by reopening XHRs | - | 2016-10-02 |
612023 | Heap-buffer-overflow in setup_frame_size_with_refs | - | 2016-10-02 |
612021 | Undefined-shift in vp9_parse_superframe_index | - | 2016-10-02 |
611887 | Security: Multiple vulnerabilities in mojo channel implementation | - | 2016-10-02 |
612049 | Heap-use-after-free in content::MediaStreamVideoSource::RemoveTrack | - | 2016-10-02 |
611352 | Heap-use-after-free in CFX_StringDataTemplate<wchar_t>::Retain() | $3,500 | 2016-10-02 |
610990 | Heap-use-after-free in blink::LayoutImage::styleDidChange | - | 2016-10-02 |
610989 | Heap-use-after-free in content::PermissionServiceImpl::CancelPendingOperations | - | 2016-10-02 |
610987 | Heap-use-after-free in v8::Isolate::VisitHandlesWithClassIds | $3,500 | 2016-10-02 |
610985 | Heap-use-after-free in blink::LayoutTextFragment::setTextFragment | - | 2016-10-02 |
610979 | Heap-use-after-free in blink::PrintContext::pageNumberForElement | - | 2016-10-02 |
610973 | Heap-use-after-free in std::__1::__tree_const_iterator<std::__1::__value_type<CFX_ByteString, CPDF_Obje | - | 2016-10-02 |
611782 | Heap-buffer-overflow in ReadScalar<unsigned | - | 2016-10-02 |
610966 | Heap-use-after-free in v8::internal::ElementsAccessorBase<v8::internal::TypedElementsAccessor< | - | 2016-10-02 |
610799 | Heap use after free in WorkerTarget::~WorkerTarget | - | 2016-10-02 |
610645 | Heap-buffer-overflow in SkAAClipBlitter::blitMask | - | 2016-10-02 |
610643 | Heap-use-after-free in blink::DeferredTaskHandler::handleDirtyAudioNodeOutputs | $3,500 | 2016-10-02 |
610600 | sandbox escape using ppapi broker | $15,000 | 2016-10-02 |
610646 | Bad-cast to const blink::WebPasswordCredential from blink::WebCredential;type_converters.cc:87:9 | - | 2016-10-02 |
610400 | Security: Bypass CORS using XHR and service workers | - | 2016-10-02 |
610441 | Security: Upgrade-Insecure-Requests does not perform Navigational Upgrades | - | 2016-10-02 |
610337 | Heap-buffer-overflow in epoll_add | - | 2016-10-02 |
609286 | extensions can bypass native messaging origin whitelisting | - | 2016-10-02 |
609260 | Security: heap-buffer-overflow in SkRegion::RunHead::findScanline | $1,000 | 2016-10-02 |
609134 | Crash in v8::Object::FindInstanceInPrototypeChain | - | 2016-10-02 |
609097 | Use-of-uninitialized-value in DetermineTextLanguage | - | 2016-10-02 |
608817 | Heap-use-after-free in blink::LayoutObject::containingBlock | $3,500 | 2016-10-02 |
608156 | Security: Heap-use-after-free in MessagingBindings::DispatchOnConnect | - | 2016-10-02 |
608104 | Security: Heap-use-after-free in RuntimeCustomBindings::GetExtensionViews | $1,500 | 2016-10-02 |
608101 | Security: Heap-use-after-free in autofill components | $1,000 | 2016-10-02 |
608100 | Security: Heap-use-after-free in AutofillAgent::FillFieldWithValue | $1,000 | 2016-10-02 |
607939 | Security: Devtools allows running privileged scripts via XSS on chrome-devtools-frontend.appspot.com | $3,500 | 2016-10-02 |
607921 | Security: Heap-use-after-free in ProfileInfoCache::SetAuthInfoOfProfileAtIndex | $1,000 | 2016-10-02 |
607722 | Heap-buffer-overflow in void v8::internal::String::WriteToFlat<unsigned short> | - | 2016-10-02 |
607721 | Use-of-uninitialized-value in woff2::ConvertWOFF2ToTTF | - | 2016-10-02 |
607652 | Tracking bug for internal fixes: Chrome M50, release 2 | - | 2016-10-02 |
607543 | An https iframe in an http page can use service worker | $1,000 | 2016-10-02 |
607483 | Security: Universal XSS converting IDL array/sequence values | - | 2016-10-02 |
618027 | Use-of-uninitialized-value in webrtc::H264::ParseRbsp | - | 2016-10-02 |
617997 | Crash in v8::internal::LargeObjectSpace::FindPage | - | 2016-10-02 |
618237 | Security: heap-use-after-free in getLineLayoutItem | $3,000 | 2016-10-02 |
617531 | Heap-buffer-overflow in webrtc::H264::ParseRbsp | - | 2016-10-02 |
617495 | Security: Universal XSS via same document navigations | $7,500 | 2016-10-02 |
617104 | Security: access-violation in blink::ScriptState::from | $1,000 | 2016-10-02 |
617635 | Crash in FixWinding | $3,500 | 2016-10-02 |
617536 | Use-of-uninitialized-value in webrtc::RtpDepacketizerH264::ProcessStapAOrSingleNalu | - | 2016-10-02 |
616970 | Heap-use-after-free in extensions::ExtensionKeybindingRegistry::IsAcceleratorRegistered | - | 2016-10-02 |
616488 | Security: web_accessible_resources can be bypassed when Chrome runs in a site isolation mode. | - | 2016-10-02 |
616386 | Security: Arbitrary Memory Read in v8 | $5,000 | 2016-10-02 |
616352 | Heap-buffer-overflow in blink::concatenateFamilyName | - | 2016-10-02 |
617097 | Heap-buffer-overflow in webrtc::RtpDepacketizerH264::ProcessStapAOrSingleNalu | - | 2016-10-02 |
615910 | upgrade-insecure-requests is not upgrading iframe sources | - | 2016-10-02 |
615820 | Heap-buffer-overflow in copy (in GURL::ReplaceComponents() ) | - | 2016-10-02 |
616119 | Heap-use-after-free in extensions::ConstructFileSystemList | - | 2016-10-02 |
614962 | AddressSanitizer: heap-buffer-overflow on address 0x7f4a13edc800 | $1,000 | 2016-10-02 |
614989 | Security: bypassing CORS by returning 308 for revalidating request for Resource previously without redirects from MemoryCache | - | 2016-10-02 |
614934 | Security: sfntly font parsing heap-buffer-overflow | $500 | 2016-10-02 |
614701 | Heap-buffer-overflow in setup_frame_size_with_refs | - | 2016-10-02 |
613915 | ASSERTION FAILED: i < m_len | - | 2016-10-02 |
613971 | Security: bypass CORS check by returning 304 from URL that previously returned 308 during revalidation from MemoryCache | - | 2016-10-02 |
613918 | Use-of-uninitialized-value in SkEvalCubicAt | - | 2016-10-02 |
614767 | Tracking bug for internal fixes: Chrome M51, release 0 | - | 2016-10-02 |
614405 | Security: update libxml to 2.9.4 | - | 2016-10-02 |
613905 | Crash in v8::base::NoBarrier_Load | - | 2016-10-02 |
613869 | Security: heap-use-after-free in blink::LayoutBox::shapeOutsideInfo | $3,000 | 2016-10-02 |
613698 | Security: mojo: Unchecked ports message payload lengths leading to buffer overflows and uafs | - | 2016-10-02 |
613626 | Credential Phishing via Transparent Authenticating Proxy Vector | $1,000 | 2016-10-02 |
613907 | Bad-cast to blink::LayoutObject from blink::PaintLayer;LayoutTableSection.cpp:831:18 | - | 2016-10-02 |
613607 | Global-buffer-overflow in XFA_GetMethodByName | - | 2016-10-02 |
613496 | Crash in v8::internal::Invoke | - | 2016-10-02 |
613488 | Crash in v8::internal::Invoke | - | 2016-10-02 |
613300 | Client-local parts of surface ID should be 64-bit and randomly generated | - | 2016-10-02 |
613266 | Security: Universal XSS via reentrancy in FrameLoader::startLoad | $7,500 | 2016-10-02 |
613160 | Security: Cisco Talos Security Advisory for Google chrome product - TALOS-CAN-0174 | $3,000 | 2016-10-02 |
612939 | Security: Wrong origin security indicators in Chrome Custom Tab | - | 2016-10-02 |
612613 | Security: Heap buffer overflows from unchecked payload_size in mojo::edj::BrokerHost::OnChannelMessage | - | 2016-10-02 |
612458 | Incorrect origin sent with message event in some cases | - | 2016-10-02 |
623186 | Crash in v8::internal::JavaScriptFrame::receiver | - | 2016-10-02 |
623193 | Stack-use-after-return in v8::internal::JsonStringifier::Result v8::internal::JsonStringifier::Serialize_< | - | 2016-10-02 |
623185 | Heap-buffer-overflow in content::WriteMemory | - | 2016-10-02 |
622522 | Security: unchecked size in mojo::Channel::Deserialize leads to memory corruption. | - | 2016-10-02 |
622351 | Bad-cast to v8::internal::PagedSpace from v8::internal::SemiSpace | - | 2016-10-02 |
622350 | Memcpy-param-overlap in CCodec_ProgressiveDecoder::GifReadMoreData | - | 2016-10-02 |
622664 | Stack-use-after-return in v8::internal::HandleBase::IsDereferenceAllowed | $3,500 | 2016-10-02 |
622183 | Security: Chrome Address Bar URL spoofing on IOS | $3,000 | 2016-10-02 |
621849 | Heap-use-after-free in cc::SurfaceManager::Destroy | - | 2016-10-02 |
621550 | Crash in v8::internal::StackTraceFrameIterator::Advance | - | 2016-10-02 |
621547 | Bad-cast to blink::BlobCallback from invalid vptr;void WTF::PartBoundFunctionImpl<;base::internal::Invoker<base::IndexSequence<0ul>, base::internal::BindState<base::internal::RunnableAdapter<void | - | 2016-10-02 |
622344 | Use-of-uninitialized-value in blink::Font::canShapeWordByWord | - | 2016-10-02 |
621115 | Use-of-uninitialized-value in blink::Font::canShapeWordByWord | - | 2016-10-02 |
621111 | Fatal error in v8::internal::List<T, P>::Add() | - | 2016-10-02 |
620949 | Security: Adobe Flash PSDK.Object Use After Free | $5,000 | 2016-10-02 |
620766 | Heap-use-after-free in cc::DrawPolygon::Split | - | 2016-10-02 |
620758 | Heap-buffer-overflow in epoll_add | - | 2016-10-02 |
620754 | Use-after-poison in blink::CrossThreadPersistentRegion::prepareForThreadStateTermination | - | 2016-10-02 |
620750 | Crash in v8::internal::Heap::AllocateHeapNumber | - | 2016-10-02 |
620694 | Incorrect packet size check leads to heap-buffer-overflow in pseudotcp | - | 2016-10-02 |
620553 | Security: V8 OOB Read(?) in GC with Array Object. | $5,000 | 2016-10-02 |
620737 | Security: Chrome does not distinguish between http and https proxies when saving passwords | - | 2016-10-02 |
620277 | Security: heap buffer overflow when calling RtpHeader::Parse on untrusted data | - | 2016-10-02 |
619405 | Security: Heap Buffer Overflow in opj_j2k_read_SQcd_SQcc | $3,500 | 2016-10-02 |
619382 | Use-of-uninitialized-value in long v8::internal::Simulator::AddWithCarry<long> | - | 2016-10-02 |
619380 | Use-of-uninitialized-value in blink::FloatingObject::unsafeClone | - | 2016-10-02 |
619378 | Crash in Sk4px::Load4 | - | 2016-10-02 |
619373 | Use-after-poison in blink::CrossThreadPersistentRegion::prepareForThreadStateTermination | - | 2016-10-02 |
619372 | Heap-buffer-overflow in usrsctp_dumppacket | - | 2016-10-02 |
619371 | Crash in SkAutoCanvasMatrixPaint::SkAutoCanvasMatrixPaint | - | 2016-10-02 |
619355 | Security: XSS issue in Google Mail | - | 2016-10-02 |
619006 | Security: Information leak in xsltFormatNumberConversion (libxslt) | $1,500 | 2016-10-02 |
618625 | Security: TSAN: data race in media::FFmpegDemuxer::~FFmpegDemuxer | $2,000 | 2016-10-02 |
609042 | Heap-buffer-overflow in Read | - | 2016-10-02 |