| 645811 | Crash in mojo::internal::Router::OnConnectionError | - | 2016-12-31 |
| 648031 | Heap-use-after-free in pp::MacroExpander::expandMacro | - | 2016-12-31 |
| 647922 | Crash in SuperBlitter::blitH | - | 2016-12-31 |
| 648935 | Crash in FindBit | - | 2016-12-31 |
| 649826 | Heap-use-after-free in CPDF_ViewerPreferences::IsDirectionR2L | - | 2016-12-31 |
| 622271 | Security: Adobe Flash ContextMenu Use After Free | $3,000 | 2016-12-30 |
| 622634 | Security: use-after-free vulnerability in flash player 22.0.0.192 | $3,000 | 2016-12-30 |
| 630544 | Security: use-after-free vulnerability in flash player 22.0.0.209 | $3,000 | 2016-12-30 |
| 630547 | Security: use-after-free vulnerability in Adobe flash player | $3,000 | 2016-12-30 |
| 640177 | Security: use-after-free vulnerability in flash player latest version | $3,000 | 2016-12-30 |
| 647791 | Heap-buffer-overflow in gpu::gles2::ShaderTranslator::Translate | - | 2016-12-30 |
| 648620 | CRASH() writes to a fixed mappable address | - | 2016-12-30 |
| 649056 | Assertion failed: !object || (object->isBox()) | - | 2016-12-30 |
| 649095 | Bad-cast to blink::LayoutBox from blink::LayoutInline;blink::LayoutBox::firstChildBox;blink::ThemePainterDefault::setupMenuListArrow | - | 2016-12-30 |
| 649058 | Use-of-uninitialized-value in blink::BoxPainter::paint | - | 2016-12-30 |
| 649599 | Crash in blink::ThemePainterDefault::setupMenuListArrow | - | 2016-12-30 |
| 502871 | Security: adobe flash NetStream.appendBytes ByteArray data Use-After-Free | $3,000 | 2016-12-29 |
| 646278 | Security: Address Bar URL Spoofing | $500 | 2016-12-29 |
| 648671 | Bad-cast to webrtc::Module from webrtc::BitrateControllerImpl;webrtc::CongestionController::TimeUntilNextProcess;webrtc::ProcessThreadImpl::Process | - | 2016-12-29 |
| 647329 | Use-after-poison in fuzz_wasm_section | - | 2016-12-28 |
| 645540 | Update It2Me host to show confirmation prompt for incoming connections. | - | 2016-12-28 |
| 648373 | Crash in v8::internal::SloppyArgumentsElementsAccessor<v8::internal::SlowSloppyArgumentsE | - | 2016-12-28 |
| 645028 | Web accessible resources checks should work with blob: and filesystem: URLs that have chrome-extension:// inner URLs | - | 2016-12-27 |
| 647612 | Heap-use-after-free in CPDF_RenderStatus::LoadSMask | - | 2016-12-27 |
| 647893 | Use-of-uninitialized-value in CPDF_DIBSource::TranslateScanline24bpp | - | 2016-12-27 |
| 647683 | Wrong security state when going back/forward after HTML5 history push | - | 2016-12-27 |
| 639750 | XSS using Dropjacking | - | 2016-12-26 |
| 646351 | Crash in v8::internal::SloppyArgumentsElementsAccessor<v8::internal::SlowSloppyArgumentsE | - | 2016-12-26 |
| 640233 | Use-of-uninitialized-value in SkGradientShaderBase::SkGradientShaderBase | - | 2016-12-25 |
| 645729 | Use-after-poison in blink::TimerBase::runInternal | $3,500 | 2016-12-25 |
| 646178 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | - | 2016-12-25 |
| 647197 | Heap-double-free in v8::internal::wasm::testing::InterpretWasmModule | - | 2016-12-24 |
| 647110 | Heap-double-free in v8::internal::wasm::testing::InterpretWasmModule | - | 2016-12-24 |
| 647027 | Heap-use-after-free in v8::internal::wasm::ThreadImpl::Execute | - | 2016-12-24 |
| 647481 | Use-of-uninitialized-value in SkGradientShaderBase::SkGradientShaderBase | - | 2016-12-24 |
| 647267 | Crash in blink::TopDocumentRootScrollerController::globalRootScroller | - | 2016-12-24 |
| 644674 | Attempting free in void v8::internal::LocalArrayBufferTracker::Free< | - | 2016-12-23 |
| 647269 | Bad-cast to blink::TopDocumentRootScrollerController from blink::RootScrollerController;blink::PaintLayerCompositor::updateClippingOnCompositorLayers;blink::PaintLayerCompositor::updateIfNeeded | - | 2016-12-23 |
| 646258 | Crash in ReadUnalignedValue<int> | - | 2016-12-23 |
| 627399 | Use-of-uninitialized-value in CCodec_TiffContext::Decode | - | 2016-12-22 |
| 621838 | Memcpy-param-overlap in CCodec_ProgressiveDecoder::JpegReadMoreData | - | 2016-12-22 |
| 645745 | Unable to block cookies | $500 | 2016-12-22 |
| 646786 | Use-of-uninitialized-value in SkMatrix44::computeTypeMask | - | 2016-12-22 |
| 646350 | Heap-use-after-free in ash::WmWindowAura::StackChildAbove | - | 2016-12-22 |
| 641239 | Use-of-uninitialized-value in blink::PointerEventManager::setPointerCapture | - | 2016-12-21 |
| 638159 | Use-of-uninitialized-value in test_runner::MockWebSpeechRecognizer::PostRunTaskFromQueue | - | 2016-12-21 |
| 642070 | Use-of-uninitialized-value in update_current_folder_get_info_cb | - | 2016-12-21 |
| 643939 | Crash in v8::internal::Invoke | - | 2016-12-21 |
| 645839 | Heap-use-after-free in cc::Scheduler::BeginImplFrameWithDeadline | - | 2016-12-21 |
| 644733 | Heap-buffer-overflow in blink::LazyLineBreakIterator::nextBreakablePositionIgnoringNBSP | - | 2016-12-21 |
| 645777 | Use-of-uninitialized-value in base::time_internal::SaturatedSub | - | 2016-12-20 |
| 645186 | Memcpy-param-overlap in CCodec_ProgressiveDecoder::JpegReadMoreData | - | 2016-12-20 |
| 645201 | Use-of-uninitialized-value in webrtc::PlayoutDelayLimits::Parse | - | 2016-12-19 |
| 645770 | Heap-buffer-overflow in void std::vector<aura::Window*, std::allocator<aura::Window*> >::_M_insert_aux<a | - | 2016-12-18 |
| 644373 | Security - Unexploitable: Integer Overflow in media::mp4::TrackRunIterator::Init leading to arbitrary size OOB read in an arbitrary offset from the buffer. | - | 2016-12-17 |
| 645034 | Use-of-uninitialized-value in blink::TraceMethodDelegate<blink::PersistentBase<blink::DOMArrayBuffer, | - | 2016-12-17 |
| 645657 | Use-of-uninitialized-value in base::Pickle::WriteBytes | - | 2016-12-17 |
| 641995 | value.isFunctionValue() | - | 2016-12-16 |
| 632709 | Heap-use-after-free in CPDFSDK_Widget::SetAppModified | - | 2016-12-15 |
| 642803 | Heap-use-after-free in cc::SurfaceManager::UnregisterBeginFrameSource | - | 2016-12-15 |
| 643726 | Heap-buffer-overflow in safe_browsing::dmg::UDIFBlock::ParseBlockData | - | 2016-12-15 |
| 643173 | Wrong security state when redirecting to HTTP | $2,000 | 2016-12-15 |
| 644182 | Heap-buffer-overflow in unibrow::Utf8::Validate | - | 2016-12-15 |
| 648971 | Chrome OS exploit: c-ares OOB write + dump_vpd_log > symlink | $100,000 | 2016-12-14 |
| 632848 | !object || (object->isBox()) | - | 2016-12-14 |
| 637899 | Heap-buffer-overflow in Decode | - | 2016-12-14 |
| 640998 | Crash in CPDF_Parser::LoadCrossRefV5 | - | 2016-12-14 |
| 643431 | Crash in v8::internal::Object::SetPropertyInternal | - | 2016-12-14 |
| 643665 | Crash inside SuperBlitter::blitH | - | 2016-12-14 |
| 643933 | Crash in SuperBlitter::blitH | - | 2016-12-14 |
| 643935 | Heap-buffer-overflow in gpu::gles2::Texture::SetLevelInfo | - | 2016-12-14 |
| 640999 | Heap-use-after-free in base::ObserverListBase<content::RenderThreadObserver>::RemoveObserver | - | 2016-12-13 |
| 642987 | Heap-buffer-overflow in unibrow::Utf8::Validate | - | 2016-12-13 |
| 643137 | Heap-use-after-free in blink::TimerBase::getTimerTaskRunner | - | 2016-12-13 |
| 643970 | Use-of-uninitialized-value in SkUnPreMultiply::PMColorToColor | - | 2016-12-13 |
| 644003 | Use-of-uninitialized-value in mojo::edk::ChannelPosix::WriteNoLock | - | 2016-12-13 |
| 624011 | Security: UAF with namespace nodes in XPointer ranges | $3,500 | 2016-12-11 |
| 638220 | Heap-buffer-overflow in test_runner::BoundsForCharacter | - | 2016-12-10 |
| 638166 | Heap-use-after-free in content::RenderFrameImpl::NavigateInternal | - | 2016-12-09 |
| 642867 | Crash in v8::internal::wasm::WasmFullDecoder::AnalyzeLoopAssignment | - | 2016-12-09 |
| 642639 | <no crash state available> | - | 2016-12-09 |
| 643071 | Crash in v8::internal::NewSpace::Verify | - | 2016-12-09 |
| 640576 | Heap-use-after-free in base::WaitableEvent::Signal | - | 2016-12-08 |
| 642028 | Use-of-uninitialized-value in void WTF::copyToVector<WTF::HashSet<blink::LayoutObject*, WTF::PtrHash<blink::La | - | 2016-12-08 |
| 497302 | Integer-overflow in sfntly::FontData::Bound | $1,000 | 2016-12-06 |
| 642063 | Crash in v8::internal::HeapObject::SizeFromMap | - | 2016-12-06 |
| 641575 | Crash in v8::internal::InstantiateObject | - | 2016-12-05 |
| 623992 | Use-of-uninitialized-value in unicodetoupper | - | 2016-12-04 |
| 622197 | Heap-buffer-overflow in u16_u8 | - | 2016-12-03 |
| 633473 | Use-of-uninitialized-value in Hunspell::spell | - | 2016-12-03 |
| 638570 | Use-of-uninitialized-value in AffixMgr::compound_check | - | 2016-12-03 |
| 638562 | Stack-buffer-overflow in SfxEntry::checkword | - | 2016-12-03 |
| 625915 | Mac: 'Press Esc to exit fullscreen' covered up by permission prompts | - | 2016-12-02 |
| 638615 | Security: heap-buffer-overflow in ImageBitmap::ImageBitmap | $5,500 | 2016-12-02 |
| 619368 | Heap-buffer-overflow in content::WriteMemory | - | 2016-12-01 |
| 631375 | Security: mbspatch: Malform patch file may access heap out of bound | - | 2016-12-01 |
| 635602 | Heap-use-after-free in content::RenderProcessHostImpl::ConnectionFilterImpl::GetInterface | - | 2016-12-01 |
| 635879 | Security: Format String Vulnerability in Chrome OS | $1,000 | 2016-12-01 |
| 638223 | Use-of-uninitialized-value in Break | - | 2016-12-01 |
| 638742 | Security: Universal XSS using ThreadDebugger::setMonitorEventsCallback | $2,000 | 2016-12-01 |
| 617124 | Use-of-uninitialized-value in WebRtcSpl_CountLeadingZeros32 | - | 2016-11-30 |
| 637594 | Security: Universal XSS using DevTools | $2,000 | 2016-11-30 |
| 639658 | Security: Navigating to "chrome://" URLs via 'about:' protocol | $500 | 2016-11-30 |
| 637546 | Security: UNKOWN in CFX_Edit_Provider::GetCharWidthW | $1,000 | 2016-11-29 |
| 639451 | Heap-use-after-free in std::__1::__tree_const_iterator<std::__1::__value_type<CFX_ByteString, CPDF_Obje | - | 2016-11-29 |
| 639984 | Heap-use-after-free in FORM_DoDocumentAAction | - | 2016-11-29 |
| 639985 | Use-of-uninitialized-value in shell::internal::InterfaceFactoryBinder<IPC::mojom::ChannelBootstrap>::BindInter | - | 2016-11-29 |
| 633306 | CSP can be abused to disclose URIs cross-origin | - | 2016-11-25 |
| 638571 | Heap-use-after-free in blink::DepthOrderedLayoutObjectList::ordered | - | 2016-11-25 |
| 638928 | !m_deletionHasBegun | - | 2016-11-25 |
| 628942 | Security: Universal XSS with ScopedPageLoadDeferrer and RemoteFrame | $17,500 | 2016-11-24 |
| 630654 | Heap-use-after-free in CPDFSDK_Document::KillFocusAnnot | $3,000 | 2016-11-24 |
| 633474 | Negative-size-param in blink::LayoutGrid::populateExplicitGridAndOrderIterator | - | 2016-11-24 |
| 638186 | Use-after-poison in blink::SVGLengthContext::convertValueToUserUnits | - | 2016-11-24 |
| 638192 | Use-after-poison in blink::ElementResolveContext::ElementResolveContext | - | 2016-11-24 |
| 638226 | Use-of-uninitialized-value in v8::internal::PointerUpdateJobTraits< | - | 2016-11-24 |
| 619381 | Crash in GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture | - | 2016-11-23 |
| 633385 | CUPS domain socket should only be openable by user chonos | - | 2016-11-23 |
| 635848 | Security: Crash in CPDF_Dictionary::GetObjectBy | $1,000 | 2016-11-23 |
| 638185 | Bad-cast to const blink::LayoutBox from blink::LayoutSVGResourcePattern;blink::PaintInvalidationState::updateForNormalChildren;blink::PaintInvalidationState::updateForChildren | - | 2016-11-23 |
| 638219 | Bad-cast to blink::LayoutBox from blink::LayoutSVGEllipse;blink::LayoutObject::positionForPoint;blink::LayoutBox::clippingRect | - | 2016-11-23 |
| 622033 | Heap-buffer-overflow in sctp_send_deferred_reset_response | - | 2016-11-22 |
| 630870 | Security: Universal XSS by intercepting a UA shadow tree | $7,500 | 2016-11-22 |
| 636268 | Security: heap-buffer-overflow in SkColorSpace | $3,500 | 2016-11-22 |
| 634557 | Security: Blob file entries aren't checked against security policy | - | 2016-11-22 |
| 628999 | Crash in blink::Geolocation::onGeolocationPermissionUpdated | - | 2016-11-21 |
| 635577 | Crash in mojo::AssociatedBinding<blink::mojom::blink::BroadcastChannelClient>::RunConnect | - | 2016-11-19 |
| 637320 | Security: Unchecked .end() iterator dereference in VTVideoDecodeAccelerator::ReusePictureBuffer | - | 2016-11-19 |
| 625404 | Security: use-after-free in AttachFilteredEvent on event_bindings.cc | $3,000 | 2016-11-18 |
| 628920 | Security: Address bar spoofing on iOS | - | 2016-11-18 |
| 625575 | Security: bypassing CORS by XHR + MemoryCache + ServiceWorker | - | 2016-11-18 |
| 633687 | Security: Full browser crash when trying to open missing 'downloaded' resource file. | - | 2016-11-18 |
| 626893 | Security: Arbitrary memory write in v8::internal::GlobalHandles::IterateNewSpaceWeakUnmodifiedRoots() | $3,000 | 2016-11-17 |
| 628542 | Heap-buffer-overflow in unibrow::Utf8::Validate | - | 2016-11-17 |
| 631368 | Crash in blink::getPropertyNameString | - | 2016-11-17 |
| 634954 | Security: Address bar spoofing with itunes page on iOS | - | 2016-11-17 |
| 636194 | Crash in void SkLinearGradient::LinearGradientContext::shade4_dx_clamp<false, false> | - | 2016-11-17 |
| 635571 | Crash in blink::EventTarget::fireEventListeners | - | 2016-11-17 |
| 622420 | Security: Type confusion in StylePropertySerializer::getCustomPropertyText. | - | 2016-11-16 |
| 632124 | Global-buffer-overflow in silk_NLSF2A | - | 2016-11-16 |
| 635574 | Use-after-poison in blink::CrossThreadPersistentRegion::shouldTracePersistentNode | $3,500 | 2016-11-16 |
| 600352 | Security: Cross-Protocol Theft from non-HTTP services via DNS rebinding + HTTP/0.9 | - | 2016-11-15 |
| 611955 | //components/filesystem/public/interfaces/*.mojom files need security review | - | 2016-11-15 |
| 618037 | Security: Devtools old remote frontend allows running privileged scripts via overwriting localStorage settings | $1,000 | 2016-11-15 |
| 633472 | Use-of-uninitialized-value in segment | - | 2016-11-15 |
| 632849 | Heap-buffer-overflow in SkA8_Blitter::blitH | - | 2016-11-13 |
| 628890 | Security: heap-buffer-overflow in opj_tcd_code_block_dec_allocate | $3,500 | 2016-11-12 |
| 628304 | Security: heap-buffer-overflow in opj_v4dwt_interleave_h | $3,500 | 2016-11-12 |
| 634238 | Security: Adobe Flash Button.blendMode setter uninitialized stack variable | - | 2016-11-12 |
| 635045 | Use-of-uninitialized-value in blink::ImagePattern::isLocalMatrixChanged | - | 2016-11-12 |
| 619429 | Security: Able to bypass permission prompt on keypress | - | 2016-11-11 |
| 624514 | Heap-buffer-overflow in CWeightTable::Calc | $3,500 | 2016-11-11 |
| 634114 | Heap-use-after-free in blink::LayoutFieldset::adjustInnerStyle | - | 2016-11-11 |
| 634394 | Security: UAF in PDFium's TimerProc() | - | 2016-11-11 |
| 627355 | Crash in _platform_memmove$VARIANT$Nehalem | - | 2016-11-10 |
| 632965 | Security: OOB read with CallSite and wasm | - | 2016-11-10 |
| 633585 | Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer | - | 2016-11-10 |
| 633471 | Use-of-uninitialized-value in GrPipeline::CreateAt | - | 2016-11-08 |
| 633486 | Tracking bug for internal fixes: Chrome M52, release 1 | - | 2016-11-08 |
| 479961 | Apply wpa_supplicant P2P vulnerability fixes | - | 2016-11-07 |
| 632634 | Security: Universal XSS with static methods and ScriptState::forHolderObject | $7,500 | 2016-11-07 |
| 610644 | Heap-buffer-overflow in ps_table_add | $1,500 | 2016-11-06 |
| 632850 | Crash in CPDFSDK_InterForm::GetWidget | - | 2016-11-06 |
| 632851 | Heap-use-after-free in CJS_Timer::KillJSTimer | - | 2016-11-06 |
| 632860 | Heap-buffer-overflow in copy | - | 2016-11-05 |
| 616429 | Security: Saving WebPage with file: resources access SMB resources | $1,000 | 2016-11-04 |
| 631052 | Use-after-poison in blink::CompositorAnimationPlayer::NotifyAnimationStarted | $3,500 | 2016-11-04 |
| 631320 | Heap-use-after-free in content::WebRTCEventLogHost::PeerConnectionRemoved | - | 2016-11-04 |
| 629919 | Security: heap-buffer-overflow in opj_tcd_update_tile_data | $5,000 | 2016-11-03 |
| 631050 | Crash in v8::internal::JSObject::UpdateAllocationSite | - | 2016-11-03 |
| 573131 | Security: some extension bindings incorrectly injected into about:blank frames | $7,500 | 2016-11-02 |
| 627414 | Crash in MaskSuperBlitter::blitH | - | 2016-11-02 |
| 630377 | Heap-use-after-free in ProfileIOData::FromResourceContext | - | 2016-11-02 |
| 629455 | Heap-buffer-overflow in SuperBlitter::blitH | - | 2016-11-02 |
| 631319 | Container-overflow in gpu::gles2::GLES2DecoderImpl::DoScheduleCALayerFilterEffectsCHROMIUM | - | 2016-11-02 |
| 631752 | Tracking bug for internal fixes: Chrome OS 52.0.2743.85 (Platform version: 8350.60.0) | - | 2016-11-02 |
| 628992 | Heap-use-after-free in SuperBlitter::blitH | - | 2016-11-01 |
| 627454 | Use-of-uninitialized-value in blink::PointerEventManager::setPointerCapture | - | 2016-11-01 |
| 630736 | Crash in segment | - | 2016-11-01 |
| 630369 | Use-of-uninitialized-value in GrShape::attemptToSimplifyPath | - | 2016-10-31 |
| 630749 | Heap-use-after-free in mojo::BindingSet<network_hints::mojom::NetworkHints>::AddBinding | - | 2016-10-31 |
| 623195 | Use-of-uninitialized-value in base::Pickle::WriteData | - | 2016-10-29 |
| 630649 | Stack-buffer-overflow in SkDCubic::searchRoots | - | 2016-10-29 |
| 399951 | Security: Cross-origin information leak via ECMAScript harmony proxies | $1,000 | 2016-10-28 |
| 614647 | Use-of-uninitialized-value in get_advance | - | 2016-10-28 |
| 621362 | Security: Universal XSS with Flash calling into JavaScript inside Node::removedFrom | $7,500 | 2016-10-28 |
| 629962 | Use-of-uninitialized-value in segment | - | 2016-10-28 |
| 628117 | Heap-use-after-free in blink::PaintController::commitNewDisplayItems | $3,500 | 2016-10-28 |
| 630378 | Use-of-uninitialized-value in SkDPoint::approximatelyEqual | - | 2016-10-28 |
| 624213 | Security: Address bar RTL character spoofing on Mac | - | 2016-10-27 |
| 624214 | Security: Address bar RTL character spoofing on iOS | - | 2016-10-27 |
| 629795 | Use-of-uninitialized-value in gpu::gles2::GLES2DecoderImpl::HandleGetBufferParameteriv | - | 2016-10-27 |
| 626186 | Crash in SkOpAngle::setSpans | - | 2016-10-26 |
| 627401 | Crash in SkOpCoincidence::mark | - | 2016-10-26 |
| 628995 | Use-of-uninitialized-value in CPWL_List_Notify::IOnInvalidateRect | - | 2016-10-26 |
| 629452 | Crash in segment | - | 2016-10-26 |
| 629454 | Use-of-uninitialized-value in containsCoincidence | - | 2016-10-26 |
| 616623 | Use-of-uninitialized-value in walk_convex_edges | - | 2016-10-25 |
| 629004 | Use-of-uninitialized-value in gpu::gles2::GLES2DecoderImpl::DoDrawBuffersEXT | - | 2016-10-25 |
| 629008 | Use-of-uninitialized-value in gpu::gles2::GLES2Implementation::WaitSyncTokenCHROMIUM | - | 2016-10-25 |
| 629435 | Crash in v8::internal::Invoke | - | 2016-10-25 |
| 623319 | URL Spoof due to subframes and NavigationEntry corruption | $2,000 | 2016-10-21 |
| 627436 | Negative-size-param in content::MediaStreamDispatcherHost::OnCancelDeviceChangeNotifications | - | 2016-10-21 |
| 627756 | Security: SEGV on unknown address in toCSSValuePair | $3,000 | 2016-10-21 |
| 627443 | Use-of-uninitialized-value in gpu::gles2::GLES2Implementation::BufferDataHelper | - | 2016-10-21 |
| 628113 | Use-of-uninitialized-value in blink::LayoutObject::setPreferredLogicalWidthsDirty | - | 2016-10-21 |
| 628130 | Stack-buffer-overflow in saturated_add | - | 2016-10-21 |
| 626790 | Crash in blink::ComputeFloatOffsetForFloatLayoutAdapter<2>::heightRemaining | - | 2016-10-20 |
| 627354 | Negative-size-param in content::WebRTCEventLogHost::PeerConnectionRemoved | - | 2016-10-20 |
| 627434 | Use-of-uninitialized-value in sk_sse41::blit_row_s32a_opaque | - | 2016-10-20 |
| 627447 | Use-of-uninitialized-value in ProfileChooserView::ButtonPressed | - | 2016-10-20 |
| 627457 | Use-after-poison in content::WebMessagePortChannelImpl::OnMessage | $3,500 | 2016-10-20 |
| 611957 | //components/leveldb/public/interfaces/leveldb.mojom needs a security review | - | 2016-10-19 |
| 618295 | Security: [PDFium]AddressSanitizer: negative-size-param | - | 2016-10-19 |
| 623168 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-19 |
| 626182 | Heap-use-after-free in blink::PaintController::commitNewDisplayItems | - | 2016-10-19 |
| 623365 | Heap Buffer Overflow in iframe URL Parse | - | 2016-10-17 |
| 579934 | Chromium allows to open popup window from Flash object without user gesture or blocking | $1,000 | 2016-10-15 |
| 610986 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-15 |
| 617648 | Heap-use-after-free in content::FilteringNetworkManager::Initialize | - | 2016-10-15 |
| 626562 | Crash in v8::internal::HandleBase::IsDereferenceAllowed | - | 2016-10-15 |
| 626792 | Heap-use-after-free in GURL::GURL | - | 2016-10-15 |
| 617105 | Security: use-after-free vulnerability in flash player | $3,000 | 2016-10-14 |
| 623072 | Use-of-uninitialized-value in containsCoincidence | - | 2016-10-14 |
| 625541 | Security: heap-buffer-overflow in opj_tcd_init_tile | $3,000 | 2016-10-14 |
| 625823 | Security: SEGV in blink::DOMWindowV8Internal::blurMethodCallback | $1,000 | 2016-10-14 |
| 625945 | Security: browser history sniffing via HSTS + CSP (bypass previous fix) | $1,000 | 2016-10-14 |
| 613949 | Extension install crashes browser at onDownloadProgress and onInstallStageChanged | $500 | 2016-10-13 |
| 625903 | Security: heap-use-after-free in blink::LayoutBox::pixelSnappedOffsetHeight | $2,000 | 2016-10-13 |
| 624818 | Use-of-uninitialized-value in gpu::gles2::GLES2Implementation::BufferDataHelper | - | 2016-10-13 |
| 623378 | Security: UAF related to XPointer range-to function | $3,500 | 2016-10-12 |
| 625752 | Crash in v8::internal::LocalArrayBufferTracker::Free<1> | - | 2016-10-12 |
| 625393 | Security: Heap-use-after-free in ScriptInjector | $1,000 | 2016-10-11 |
| 616907 | Security: Universal XSS using a ScopedPageLoadDeferrer bypass | $8,000 | 2016-10-10 |
| 619379 | CharacterData::setData() should handle first-letter correctly | - | 2016-10-06 |
| 620952 | i < m_len | - | 2016-10-06 |
| 624713 | Security: Calling from WASM to JS should not pass the global object | - | 2016-10-06 |
| 291417 | Security: <webview>/App Request Contexts may not be so isolated | - | 2016-10-05 |
| 561978 | Vulnerability reported in media-libs/libpng | - | 2016-10-05 |
| 609382 | Security: Use after free of task_struct in Mali Midgard driver. | - | 2016-10-05 |
| 612050 | Heap-use-after-free in views::Widget::OnNativeWidgetDestroying | - | 2016-10-05 |
| 609680 | Chrome For Android Address Bar Spoofing Issue Due To Mishandling Of RTL Characters | $3,000 | 2016-10-05 |
| 617882 | Crash in v8::internal::PointerUpdateJobTraits< | - | 2016-10-05 |
| 618333 | Security: Parameter sanitization failure in DevTools leads to privileged script execution | $2,000 | 2016-10-05 |
| 619414 | Security: Devtools has Insuffient sanitization of remoteBase parameter | $2,000 | 2016-10-05 |
| 620981 | Crash in _platform_bzero$VARIANT$Merom | - | 2016-10-05 |
| 621843 | Heap-buffer-overflow in float blink::ShapeResultSpacing::computeSpacing<unsigned short> | - | 2016-10-05 |
| 623985 | Use-after-poison in blink::PersistentBase<blink::WorkerWebSocketChannel::Bridge, | $3,500 | 2016-10-05 |
| 623996 | Use-of-uninitialized-value in blink::LineBoxList::deleteLineBoxes | - | 2016-10-05 |
| 617084 | Crash in v8::internal::HandleBase::IsDereferenceAllowed | - | 2016-10-04 |
| 619377 | Bad-cast to blink::WebGLObject from invalid vptr;blink::WebGLProgram::deleteObjectImpl;blink::WebGLSharedObject::detachContextGroup | - | 2016-10-04 |
| 621095 | SIGSEGV, RIP = 0x0 | - | 2016-10-04 |
| 118642 | Heap-use-after-free in v8::internal::JSObject::GetElementWithInterceptor | $1,000 | 2016-10-02 |
| 118662 | Regression(r109014): Heap-use-after-free in WebCore::InlineTextBox::isLineBreak | $500 | 2016-10-02 |
| 118593 | Heap-use-after-free in WebCore::SVGStyledElement::buildPendingResourcesIfNeeded | $1,000 | 2016-10-02 |
| 118490 | Heap-use-after-free in WebCore::RenderObject::containingBlock | $1,000 | 2016-10-02 |
| 118467 | open.call(other_window) circumvents check in other_window.open() | - | 2016-10-02 |
| 118633 | Security: Frame sniffing is not fixed | - | 2016-10-02 |
| 118414 | Heap use after free on chrome_content_browser_client.cc with webrtc | $1,000 | 2016-10-02 |
| 118374 | Long autofilled value causes render issue | - | 2016-10-02 |
| 118273 | ZDI-CAN-1528: Webkit HTMLMedia Element beforeLoad Remote Code Execution Vulnerability | - | 2016-10-02 |
| 118227 | Security: cross-origin iframes can be resized from within in M18 | - | 2016-10-02 |
| 118018 | Heap-buffer-overflow in S32_opaque_D32_nofilter_DXDY | - | 2016-10-02 |
| 118317 | Popup blocker bypass triggering mouse event on tag with rel=noreferrer | - | 2016-10-02 |
| 118185 | Heap-use-after-free in WebCore::V8HTMLBodyElement::wrapSlow | - | 2016-10-02 |
| 117890 | Use-after-free in CrashGenerationServer | - | 2016-10-02 |
| 117912 | Heap-buffer-overflow in memcmp | - | 2016-10-02 |
| 117794 | [LangFuzz] Crash on heap with invalid read through GetPropertyWithCallback | $500 | 2016-10-02 |
| 117736 | No permission prompt when loading unpacked extension with NPAPI plugin | - | 2016-10-02 |
| 117728 | Heap-use-after-free in WebCore::InlineBox::root | $1,000 | 2016-10-02 |
| 117724 | Event handlers firing during Text::splitText trigger use-after-free. | - | 2016-10-02 |
| 118009 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 0ul>::append<unsigned short> | - | 2016-10-02 |
| 117889 | Dangerous download warnings are suppressed for a larger class of downloads than are handled by SafeBrowsing | - | 2016-10-02 |
| 117698 | Heap-use-after-free in WebCore::RenderLayer::addChild | $1,000 | 2016-10-02 |
| 117696 | Heap-use-after-free in WebCore::RenderBlock::addPositionedFloats | - | 2016-10-02 |
| 117674 | Heap-use-after-free in WebCore::GraphicsContext3D::getExtensions | - | 2016-10-02 |
| 117672 | Uptake angle security fix | - | 2016-10-02 |
| 117656 | Pwnium bug: GPU memory corruption | - | 2016-10-02 |
| 117627 | Security: IPC Channel does not validate the listener. | - | 2016-10-02 |
| 117620 | Pwnium bug: Prerendering issues with NACL | $60,000 | 2016-10-02 |
| 117715 | LoadExtension binding in chrome://extensions/ is too permissive | - | 2016-10-02 |
| 117583 | Iframe hijacking from Pwnium | - | 2016-10-02 |
| 117588 | Security: Memory Corruption in MaskSuperBlitter | $1,000 | 2016-10-02 |
| 117545 | ICU lang buffer overflow | - | 2016-10-02 |
| 117471 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | $1,000 | 2016-10-02 |
| 117446 | App popup user gesture exemption should be based on process type, not just extent | - | 2016-10-02 |
| 117418 | Security: Don't grant WebUI bindings to a process shared with normal views | - | 2016-10-02 |
| 117417 | Security: Don't let a normal web renderer navigate to a privileged URL | - | 2016-10-02 |
| 117413 | Heap-use-after-free in WebCore::RenderScrollbar::getScrollbarPseudoStyle | - | 2016-10-02 |
| 117409 | Chrome: Crash Report - Stack Signature: v8::internal::MarkCompactCollector::RecordS... | - | 2016-10-02 |
| 117400 | Uptake fixes on weak node iteration patterns | - | 2016-10-02 |
| 117511 | Heap-use-after-free in WTF::equal | - | 2016-10-02 |
| 117335 | Occasional heap-use-after-free in non-virtual thunk to AudioDevice::OnStateChanged | $500 | 2016-10-02 |
| 117341 | Heap-use-after-free in MessageLoop::AddToIncomingQueue | $1,000 | 2016-10-02 |
| 117230 | Part 2 of Pwnium Bug | - | 2016-10-02 |
| 117226 | Part 1 of Pwnium Bug: UXSS | $60,000 | 2016-10-02 |
| 117150 | REGRESSION(wk109285): Heap-use-after-free in WebCore::Document::nodeChildrenWillBeRemoved | $1,000 | 2016-10-02 |
| 117110 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
| 116994 | Heap-use-after-free in chrome::ChromeContentBrowserClient::RequestMediaAccessPermission | - | 2016-10-02 |
| 116967 | Heap-buffer-overflow in WebCore::SVGUseElement::instanceForShadowTreeElement | - | 2016-10-02 |
| 116927 | Heap-buffer-overflow in av_freep | $1,000 | 2016-10-02 |
| 116806 | Heap-use-after-free in WebCore::RenderInline::continuationBefore | - | 2016-10-02 |
| 116746 | Heap-use-after-free in WebCore::RenderBlock::splitBlocks | $1,000 | 2016-10-02 |
| 116637 | Renderer process crash when doing WebGL canvas to 2D canvas drawImage() | - | 2016-10-02 |
| 116524 | Security: Off-by-one in OTS resulting in arbitrary code execution | - | 2016-10-02 |
| 116461 | Heap-use-after-free in WebCore::CSSCrossfadeValue::~CSSCrossfadeValue | $1,000 | 2016-10-02 |
| 116405 | Mitigate stale layout root bugs | - | 2016-10-02 |
| 116398 | Security: SSL proxy seems to not care about the cert | - | 2016-10-02 |
| 116474 | Merge SVG use fix to stable | - | 2016-10-02 |
| 121926 | Heap-buffer-overflow in WebCore::FEConvolveMatrix::platformApplySoftware | - | 2016-10-02 |
| 121937 | glGetProgramInfoLog regression in ANGLE | - | 2016-10-02 |
| 121734 | Heap-use-after-free in WebCore::V8AbstractEventListener::~V8AbstractEventListener | - | 2016-10-02 |
| 121726 | Sandbox IPC length checking race | - | 2016-10-02 |
| 121703 | Crash in NSMutableRLEArray replaceObjectsInRange:withObject:length with long URL | - | 2016-10-02 |
| 121692 | Heap-use-after-free in WebCore::SelectorChecker::checkOneSelector | - | 2016-10-02 |
| 121645 | Heap-use-after-free in WebCore::RenderBlock::removeFloatingObject | - | 2016-10-02 |
| 121899 | Security: use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer() | $1,000 | 2016-10-02 |
| 121736 | Heap-use-after-free in WebCore::EventDispatcher::dispatchEvent | - | 2016-10-02 |
| 121347 | Heap-buffer-overflow in WebCore::RenderBlock::LineBreaker::nextLineBreak | $500 | 2016-10-02 |
| 121524 | Use after free with reflections and composited layers | - | 2016-10-02 |
| 121206 | Heap-buffer-overflow in WebCore::HTMLSelectElement::setRecalcListItems | - | 2016-10-02 |
| 121128 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::append<unsigned short> | - | 2016-10-02 |
| 120977 | Crash in texSubImage2D on Mozilla's WebGL performance regression tests | - | 2016-10-02 |
| 121269 | invalid cast in WebCore::toHTMLElement / WebCore::HTMLFieldSetElement::disabledAttributeChanged | - | 2016-10-02 |
| 121223 | Heap-use-after-free in WebCore::WorkerThreadableWebSocketChannel::Bridge::mainThreadCreateWebSocketChannel | $500 | 2016-10-02 |
| 121407 | [LangFuzz] Invalid write in v8::internal::ElementsAccessorBase<...>::CopyElements | $1,000 | 2016-10-02 |
| 120648 | UNKNOWN in SkARGB32_Blitter::blitV | $500 | 2016-10-02 |
| 120457 | Global-buffer-overflow in WebCore::InlineTextBox::isLineBreak | - | 2016-10-02 |
| 120711 | Heap-use-after-free in WebCore::Element::recalcStyle | $1,000 | 2016-10-02 |
| 120944 | Use-after-free due to issues in counter layout. | $1,000 | 2016-10-02 |
| 120912 | Heap-use-after-free in WebCore::RenderText::removeTextBox | $1,000 | 2016-10-02 |
| 120320 | Flash Broker Bypass 0x2B (CVE-2012-0724) | - | 2016-10-02 |
| 120318 | Flash Broker Bypass 0x2D (CVE-2012-0725) | - | 2016-10-02 |
| 120222 | Heap-use-after-free in WebCore::RenderTableSection::paintCell | $1,000 | 2016-10-02 |
| 120205 | Security: <svg:use> elements in the parser can create elements not marked as created by the parser | - | 2016-10-02 |
| 120404 | Heap-buffer-overflow in WebCore::Font::codePath | - | 2016-10-02 |
| 120037 | Heap-use-after-free in WebCore::ContainerNode::resumePostAttachCallbacks | $1,000 | 2016-10-02 |
| 120007 | Heap-use-after-free in WebCore::WorkerEventQueue::close | - | 2016-10-02 |
| 120403 | Heap-use-after-free in WebCore::ContainerNode::insertBefore | - | 2016-10-02 |
| 120189 | Heap-use-after-free in WebCore::V8RecursionScope::didLeaveScriptContext | - | 2016-10-02 |
| 119926 | Use after free in v8::internal::IncrementalMarking::Step | $1,000 | 2016-10-02 |
| 119501 | Heap-use-after-free in WebCore::SVGStyledElement::buildPendingResourcesIfNeeded | $1,000 | 2016-10-02 |
| 119429 | UNKNOWN in v8::Message::GetScriptResourceName | $500 | 2016-10-02 |
| 120006 | Heap-use-after-free in WebCore::RenderBlock::finishDelayUpdateScrollInfo | - | 2016-10-02 |
| 119525 | Heap-use-after-free in WebCore::ApplyStyleCommand::applyInlineStyleToNodeRange | $1,000 | 2016-10-02 |
| 119281 | Heap-use-after-free in WebCore::GenericEventQueue::~GenericEventQueue | $500 | 2016-10-02 |
| 119230 | Heap-use-after-free in WebCore::RenderBlock::splitBlocks | - | 2016-10-02 |
| 119150 | Sandboxed processes should not be able to open other sandboxed processes | - | 2016-10-02 |
| 119084 | Heap-use-after-free in utext_setNativeIndex_46 | - | 2016-10-02 |
| 118970 | GPU process crash below DoDrawArrays (Nvidia) | $500 | 2016-10-02 |
| 119305 | Heap-use-after-free in WebCore::Node::~Node | $1,000 | 2016-10-02 |
| 119250 | GPU, Plugin, and NaCl processes have PROCESS_DUP_HANDLE permission on renderer processes | - | 2016-10-02 |
| 118803 | Heap-use-after-free in WebCore::SVGTextLayoutAttributesBuilder::fillCharacterDataMap | - | 2016-10-02 |
| 118784 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::insert<unsigned short> | - | 2016-10-02 |
| 118853 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 118664 | Security: Swapped out URL must be a unique origin | - | 2016-10-02 |
| 118721 | Extensions resources can be fetched across incognito | - | 2016-10-02 |
| 116162 | Heap-buffer-overflow in wk_png_inflate | - | 2016-10-02 |
| 116128 | Content scripts should never be run in the webstore isolate | - | 2016-10-02 |
| 116093 | Heap-buffer-overflow in WebCore::SVGDocumentExtensions::removeAnimationElementFromTarget | $1,000 | 2016-10-02 |
| 116069 | WebCore::MediaStreamListInternal::itemCallback | $500 | 2016-10-02 |
| 116224 | Heap-use-after-free in WebCore::FrameLoader::urlSelected | - | 2016-10-02 |
| 115998 | Heap-use-after-free in WebCore::RenderMenuList::addChild | - | 2016-10-02 |
| 115862 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 115756 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 115754 | Heap-use-after-free in WebCore::RenderLayer::addChild | $1,000 | 2016-10-02 |
| 115695 | Heap-buffer-overflow in WebCore::StaticNodeList::itemWithName | $1,000 | 2016-10-02 |
| 115681 | Heap-use-after-free in WebCore::RenderBox::enclosingFloatPaintingLayer | $1,000 | 2016-10-02 |
| 115680 | Heap-use-after-free in WebCore::RenderListItem::updateMarkerLocation | - | 2016-10-02 |
| 115807 | Heap-use-after-free in WebCore::RenderMenuList::addChild | - | 2016-10-02 |
| 116027 | Heap-buffer-overflow in WebCore::InlineFlowBox::addToLine | - | 2016-10-02 |
| 115159 | Security: Setting innerText allows DOMSubtreeModified listeners to cause crashes | - | 2016-10-02 |
| 115028 | Bad cast in splitAnonymousBlocksAroundChild (part 3) | $1,000 | 2016-10-02 |
| 115003 | Heap-use-after-free in WebCore::RenderObject::previousInPreOrder | - | 2016-10-02 |
| 115299 | Use-after-free in AudioDeviceThread::Callback::InitializeOnAudioThread | $500 | 2016-10-02 |
| 115471 | Heap-buffer-overflow in SkAlphaRuns::add | $1,000 | 2016-10-02 |
| 114924 | Bad cast in splitAnonymousBlocksAroundChild | $1,000 | 2016-10-02 |
| 114911 | Heap-buffer-overflow in WebCore::Element::setAttribute | - | 2016-10-02 |
| 114858 | Heap-use-after-free in WebCore::RenderTableSection::willBeDestroyed | - | 2016-10-02 |
| 114960 | Heap-use-after-free in WebCore::SVGTextLayoutAttributesBuilder::fillCharacterDataMap | - | 2016-10-02 |
| 114219 | Heap-use-after-free in WebCore::RenderTableSection::nodeAtPoint | $1,000 | 2016-10-02 |
| 114152 | Heap-use-after-free in WebCore::InspectorStyleSheet::deleteRule | - | 2016-10-02 |
| 114144 | Crash by clicking the time field of maps.google.com | - | 2016-10-02 |
| 114068 | Heap-use-after-free in WebCore::HTMLElement::isPresentationAttribute | $1,000 | 2016-10-02 |
| 114056 | Heap-buffer-overflow in WebCore::previousBoundary | $500 | 2016-10-02 |
| 114054 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 0ul>::append<unsigned short> | $500 | 2016-10-02 |
| 113924 | [LangFuzz] Crash at v8::internal::HashTable<...>::FindEntry with invalid read | $1,000 | 2016-10-02 |
| 114342 | Stack-buffer-overflow at strcpy | $1,000 | 2016-10-02 |
| 113837 | Heap-use-after-free in WebCore::Document::unregisterForPageCacheSuspensionCallbacks | $1,000 | 2016-10-02 |
| 113800 | Heap-use-after-free in WebCore::RenderBlock::computeOverflow | - | 2016-10-02 |
| 113902 | Heap-use-after-free in WebCore::InlineBox::root | $1,000 | 2016-10-02 |
| 113799 | Heap-use-after-free in WebCore::RenderTable::layout | - | 2016-10-02 |
| 113801 | Heap-use-after-free in WebCore::RenderBlock::outlineStyleForRepaint | - | 2016-10-02 |
| 113733 | Security: Flash deployed via component updater runs outside the sandbox | - | 2016-10-02 |
| 113755 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
| 113707 | Heap-use-after-free in WebCore::RenderQuote::placeQuote | $1,000 | 2016-10-02 |
| 113690 | Heap-use-after-free in WebCore::RenderButton::removeChild | - | 2016-10-02 |
| 113567 | Heap-use-after-free in WebCore::RenderRegion::setRegionBoxesRegionStyle | - | 2016-10-02 |
| 113562 | Heap-use-after-free in WebCore::NavigationScheduler::schedule | - | 2016-10-02 |
| 113730 | Integer wrap in CSSParser::quoteCSSString() can cause a buffer overflow | - | 2016-10-02 |
| 113497 | Heap-use-after-free in WebCore::InlineFlowBox::computeUnderAnnotationAdjustment | $1,000 | 2016-10-02 |
| 113496 | Links in settings page (like learn more, google dashboard) are opened in the webui renderer process | - | 2016-10-02 |
| 113439 | Bad casts due to issues in splitAnonymousBlocksAroundChild | $1,000 | 2016-10-02 |
| 113415 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 113258 | Bad cast in WebCore::RenderBlock::createLineBoxes | $1,000 | 2016-10-02 |
| 113178 | Adding a ShadowRoot to a SELECT element causes crashes | - | 2016-10-02 |
| 113174 | Attaching a ShadowRoot to a VIDEO element causes heap-use-after-free | - | 2016-10-02 |
| 113160 | Security: Tracking bug for WK77971 - Replaces the [CheckNodeSecurity] IDL attribute | - | 2016-10-02 |
| 113119 | Security: Report bad translation link uses http:// | - | 2016-10-02 |
| 112976 | Heap-use-after-free in vorbis_decode_frame | - | 2016-10-02 |
| 112961 | TCP and UDP IPCs should not be exposed to arbitrary renderers | - | 2016-10-02 |
| 112983 | Browser crash with FTP video source | - | 2016-10-02 |
| 125462 | Security: libxml2 1-byte heap-buffer-overflow in xmlXPtrEvalXPtrPart | $1,500 | 2016-10-02 |
| 125436 | Heap-use-after-free in WebCore::HTMLFormControlElement::disabled | - | 2016-10-02 |
| 125249 | Heap-buffer-overflow in seg_to | - | 2016-10-02 |
| 125225 | Domui process can be ptraced from a compromised renderer leading to sandbox escape, take 2 | - | 2016-10-02 |
| 125159 | Chrome chrashes when pressing back button on a page that is still downloading a big gif image | $1,337 | 2016-10-02 |
| 125151 | Heap-use-after-free in WebCore::Node::compareDocumentPosition | - | 2016-10-02 |
| 125010 | Stealing AutoFill data with window.getSelection() before users actually select form contents | - | 2016-10-02 |
| 125494 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::processEndTag | - | 2016-10-02 |
| 125374 | Heap-use-after-free in WebCore::RenderSVGContainer::paint | $1,000 | 2016-10-02 |
| 124992 | Heap-use-after-free in WebCore::swapInNodePreservingAttributesAndChildren | - | 2016-10-02 |
| 124923 | Heap-use-after-free in WebCore::parseToDoubleForNumberType | - | 2016-10-02 |
| 124919 | Heap-use-after-free in WebCore::RenderBlock::addOverflowFromFloats | - | 2016-10-02 |
| 124895 | Heap-use-after-free in WebCore::ScriptController::executeIfJavaScriptURL | - | 2016-10-02 |
| 124893 | Heap-buffer-overflow in WebCore::HTMLOptionElement::selected | - | 2016-10-02 |
| 124870 | Heap-use-after-free in WebCore::InsertParagraphSeparatorCommand::doApply | - | 2016-10-02 |
| 124868 | Heap-use-after-free in WebCore::RenderObject* WebCore::bidiNextShared<WebCore::BidiResolver<WebCore::InlineIterator, WebCor | - | 2016-10-02 |
| 124836 | NSS should reject DH public values equal to one | - | 2016-10-02 |
| 125000 | Heap-buffer-overflow in WTF::VectorMover<false, WebCore::Attribute>::move | - | 2016-10-02 |
| 124924 | Heap-buffer-overflow in WebCore::XPath::sortBlock | - | 2016-10-02 |
| 124652 | Heap-buffer-overflow in SkDashPathEffect::SkDashPathEffect | - | 2016-10-02 |
| 124625 | Chrome: Crash Report - Stack Signature: WebCore::npObjectNamedGetter<WebCore::V8HTM... | - | 2016-10-02 |
| 124617 | Heap-buffer-overflow in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
| 124669 | Heap-use-after-free in WebCore::SVGLength::value | - | 2016-10-02 |
| 124530 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
| 124594 | UNKNOWN in v8::internal::MarkCompactCollector::PrepareThreadForCodeFlushing | $500 | 2016-10-02 |
| 124479 | Use after free in PDF with corrupt CID font encoding name | - | 2016-10-02 |
| 124356 | Heap-use-after-free in WebCore::GraphicsContext::restore | $1,000 | 2016-10-02 |
| 124263 | OOB read with PDF in cell sorting | - | 2016-10-02 |
| 124228 | Security: Component updater parses unauthenticated XML with libxml in the browser process | - | 2016-10-02 |
| 124216 | Security: MSVR:159 - Google Chrome NPAPI Plugin Insecure Loading Elevation of Privilege Vulnerability | - | 2016-10-02 |
| 124191 | OOB read in PDF when parsing / processing text | - | 2016-10-02 |
| 124190 | OOB read, off-by-one in PDF predictor code with specific decode parameters | - | 2016-10-02 |
| 124184 | OOB read with 1bpp image and ICC profile | - | 2016-10-02 |
| 124183 | OOB read in PDF fax codec | - | 2016-10-02 |
| 124389 | Heap-use-after-free in WebCore::TargetListener::clear | - | 2016-10-02 |
| 124182 | Out of bounds write in PDF with sample function with lots of inputs | - | 2016-10-02 |
| 124179 | PDF crash under ASAN with character maps | - | 2016-10-02 |
| 123929 | Out-of-bounds read in PDF with undersized "O" key and revision 3 crypto | - | 2016-10-02 |
| 123858 | Use-after-free in WebPagePopupImpl instance | - | 2016-10-02 |
| 123735 | OOB reads in PDF AES support due to buffer mismanagement | - | 2016-10-02 |
| 123733 | Out-of-bounds reads with bad parameters to PDF "sampled function" function | - | 2016-10-02 |
| 123709 | Breakpad ClientInfo::PopulateCustomInfo() integer wrap leads to heap overflow | - | 2016-10-02 |
| 123656 | OOB read in PDF whilst scanning for "startxref" | - | 2016-10-02 |
| 123631 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | - | 2016-10-02 |
| 123544 | Heap-use-after-free in WebCore::CachedResource::checkNotify | - | 2016-10-02 |
| 123530 | Heap-use-after-free in AutocompleteMatch::AutocompleteMatch | - | 2016-10-02 |
| 123484 | Global-buffer-overflow in WebCore::InlineTextBox::isLineBreak | - | 2016-10-02 |
| 123481 | Security: ERROR: AddressSanitizer heap-buffer-overflow on address 0x7fde15ff9890 at pc 0x7fde364c5034 | $1,000 | 2016-10-02 |
| 123105 | Heap-buffer-overflow in Color32_SSE2 | - | 2016-10-02 |
| 123054 | Security: renderer can grant itself read permissions to arbitrary files | - | 2016-10-02 |
| 123029 | OOB write in SkARGB32_Black_Blitter::blitAntiH -> sk_memset32_SSE2 | $1,000 | 2016-10-02 |
| 123012 | Chrome: Crash Report - Stack Signature:WebCore::V8BindingPerContextData::constructorForType(WebCore::WrapperTypeInfo *) | - | 2016-10-02 |
| 122925 | Security: Autofill info can be captured by innocuous social engineering | $1,000 | 2016-10-02 |
| 122865 | Heap-use-after-free in SkCanvas::internalDrawBitmapRect | - | 2016-10-02 |
| 122760 | Heap-use-after-free in WebCore::RenderTable::computePreferredLogicalWidths | - | 2016-10-02 |
| 122692 | UNKNOWN in /lib/libc-2.11.1.so+Unknown | - | 2016-10-02 |
| 122681 | [LangFuzz] CHECK(fixed_size + height_in_bytes == input_frame_size) failed or crash with invalid read | $500 | 2016-10-02 |
| 122654 | Chrome: Crash Report: SocketStreamDispatcherHost::CancelSSLRequest | - | 2016-10-02 |
| 122586 | Global-buffer-overflow in HB_TibetanShape | - | 2016-10-02 |
| 122585 | Security: stack-buffer-overflow in WebCore::GlyphPage::fill with surrogate characters | $500 | 2016-10-02 |
| 122573 | Heap-use-after-free in WebCore::CachedRawResource::didAddClient | - | 2016-10-02 |
| 122854 | Security: Potential (racy) use after free error in DownloadResourceHandler::OnResponseCompletedInternal | - | 2016-10-02 |
| 122503 | Heap-buffer-overflow in erode | - | 2016-10-02 |
| 122337 | [LangFuzz] Crash on heap with invalid write (32 bit only). | $1,000 | 2016-10-02 |
| 122208 | GCing a node observed by a WebKitMutationObserver can cause an invalid HashSet iterator | - | 2016-10-02 |
| 122029 | Heap-buffer-overflow in WebCore::InlineFlowBox::addToLine | - | 2016-10-02 |
| 122014 | Heap-use-after-free in WorkerEventQueue::close | - | 2016-10-02 |
| 121968 | Heap-use-after-free in WebCore::GraphicsLayer::willBeDestroyed | - | 2016-10-02 |
| 122562 | Heap-use-after-free in ModuleSystem::LazyFieldGetter | $1,000 | 2016-10-02 |
| 112847 | Bad cast in addChildToAnonymousColumnBlocks | $1,000 | 2016-10-02 |
| 112833 | Heap-use-after-free in webkit_media::BufferedResourceLoader::Start | $1,000 | 2016-10-02 |
| 112822 | Security: Heap-buffer-overflow in png_decompress_chunk | $1,337 | 2016-10-02 |
| 112814 | Safe Browsing client doesn't always check for MAC field in response | - | 2016-10-02 |
| 112775 | Heap-use-after-free in WebCore::Node::traverseNextNode | - | 2016-10-02 |
| 112764 | Heap-use-after-free in RendererAccessibility::SendPendingAccessibilityNotifications | - | 2016-10-02 |
| 112738 | Security: User Interface - infobar confusion, spamming, and spoofing | - | 2016-10-02 |
| 112735 | Bad cast in FormSubmission::create | - | 2016-10-02 |
| 112694 | Heap-use-after-free in WebCore::Node::normalize | - | 2016-10-02 |
| 112670 | avcodec_53!ff_h264_get_profile - crash | $500 | 2016-10-02 |
| 112451 | X509UserCertResourceHandler::OnResponseCompleted crash | - | 2016-10-02 |
| 112443 | [Mac] Regular SSL certificate incorrectly displayed with EV color badge | - | 2016-10-02 |
| 112542 | Heap-use-after-free in WebCore::TextIterator::rangeFromLocationAndLength | - | 2016-10-02 |
| 112411 | Heap-use-after-free in WebCore::SVGUseElement::expandSymbolElementsInShadowTree | $1,000 | 2016-10-02 |
| 112391 | Heap-use-after-free in ExtensionHost | - | 2016-10-02 |
| 112339 | Security: chrome allows TDR looping leading to win7 OS crash through page refresh html tag + WebGL | - | 2016-10-02 |
| 112325 | Security: Copy-paste preserves <embed> tags containing active content | - | 2016-10-02 |
| 112317 | Heap-buffer-overflow in WebCore::Font::codePath | $500 | 2016-10-02 |
| 112259 | Heap-use-after-free in WebCore::EventTarget::dispatchEvent | $500 | 2016-10-02 |
| 112236 | Security: Chrome translation script downloaded over HTTP | - | 2016-10-02 |
| 112212 | Heap-use-after-free in WebCore::ContainerNode::appendChild | $2,000 | 2016-10-02 |
| 112151 | Heap-use-after-free in WebCore::RenderRegion::setRegionBoxesRegionStyle | $1,000 | 2016-10-02 |
| 112093 | Heap-use-after-free in WebCore::Node::dispatchSubtreeModifiedEvent | - | 2016-10-02 |
| 112055 | Heap-buffer-overflow in WebCore::CSSParser::lex | - | 2016-10-02 |
| 111779 | Heap-use-after-free in WebCore::SubframeLoader::loadSubframe | $1,000 | 2016-10-02 |
| 111748 | Heap-use-after-free in WebCore::SVGElement::removedFromDocument | $1,000 | 2016-10-02 |
| 111656 | Security: Accessibility bad cast | - | 2016-10-02 |
| 111575 | Security: NaCl dynamic code modification allows direct calls inside existing super instructions. | - | 2016-10-02 |
| 111491 | AddressSanitizer reports a heap-use-after-free in icu_46::RuleBasedBreakIterator::handleNext in DownloadTest.CrxLargeTheme (browser_tests) on Chrome OS | - | 2016-10-02 |
| 111088 | Heap-use-after-free in WebCore::FrameLoader::checkTimerFired | - | 2016-10-02 |
| 111467 | Heap-buffer-overflow in WebCore::SVGSVGElement::currentViewBoxRect | $1,000 | 2016-10-02 |
| 110849 | Heap-buffer-overflow in matroska_parse_block | - | 2016-10-02 |
| 110764 | Heap-use-after-free in WebCore::DocumentLoader::detachFromFrame | $1,000 | 2016-10-02 |
| 110723 | Heap-use-after-free in WebCore::RenderSVGResourceContainer::markAllClientsForInvalidation | - | 2016-10-02 |
| 111342 | Heap-use-after-free in AudioDevice::FireRenderCallback | - | 2016-10-02 |
| 110559 | Heap-buffer-overflow in GPU ShaderTranslator | - | 2016-10-02 |
| 110374 | Heap-use-after-free in WebCore::EventHandler::mouseMoved | $1,000 | 2016-10-02 |
| 110360 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | - | 2016-10-02 |
| 110277 | Heap-buffer-overflow in xsltCompilePatternInternal | $500 | 2016-10-02 |
| 110172 | Heap-buffer-overflow in SkAlphaRuns::add | $1,000 | 2016-10-02 |
| 110545 | Security: AssociatedURLLoader exposes non-whitelisted response headers when loading with access control (CORS) | - | 2016-10-02 |
| 110076 | Heap-use-after-free in WebCore::CompositeEditCommand::ensureComposition | - | 2016-10-02 |
| 109743 | Heap-use-after-free in WebCore::CSSStyleSelector::matchRulesForList | $1,000 | 2016-10-02 |
| 109717 | Security: crash when viewing a certificate without issuer signature | - | 2016-10-02 |
| 109716 | Heap-use-after-free in xsltParseGlobalVariable | $1,000 | 2016-10-02 |
| 109691 | Security: Losing user-set pin data on HSTS header receipt | - | 2016-10-02 |
| 110112 | Heap-use-after-free in WebCore::FrameView::forceLayoutParentViewIfNeeded | $1,000 | 2016-10-02 |
| 109912 | Security: read sandbox escape: NaCl validator for x86-64 allow REP string instructions to have out-of-bound source addresses | - | 2016-10-02 |
| 109623 | Chrome: Crash Report - Stack Signature: WebKit::WebMediaPlayerClientImpl::loadInter... | - | 2016-10-02 |
| 109574 | Potential XSS attack with [0x8E][0xE3] in EUC-JP page | $500 | 2016-10-02 |
| 109556 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::HTMLTreeBuilder | $1,000 | 2016-10-02 |
| 109411 | Regression: Crash in WebCore::DynamicSubtreeNodeList::length() | - | 2016-10-02 |
| 109245 | Security: Chrome Drag Spoofing | - | 2016-10-02 |
| 109664 | safe_browsing::SignatureUtil::CheckSignature() - crash | - | 2016-10-02 |
| 109094 | Possible wild read in internal PDF-reader | - | 2016-10-02 |
| 108958 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 129158 | Heap-use-after-free in WebCore::AccessibilityObject::getAttribute | - | 2016-10-02 |
| 129191 | UNKNOWN in WebCore::HTMLDocumentParser::prepareToStopParsing | $1,000 | 2016-10-02 |
| 128971 | Heap-use-after-free in WebCore::InlineBox::deleteLine | - | 2016-10-02 |
| 128711 | Run-in UAF crashes relating to generated content and inline line box tree not clearing. | - | 2016-10-02 |
| 128704 | Crash when opening and closing chrome://chrome | - | 2016-10-02 |
| 128688 | Heap-buffer-overflow in gpu::gles2::GLES2Implementation::TexSubImage2DImpl | - | 2016-10-02 |
| 128800 | Use after free in WebCore::SVGTextLayoutAttributesBuilder::fillCharacterDataMap | - | 2016-10-02 |
| 128597 | RenderViewImpl's shared_popup_counter_ isn't incremented properly | - | 2016-10-02 |
| 128498 | Heap-buffer-overflow in WebCore::CSSSelector::specificityForOneSelector | - | 2016-10-02 |
| 128497 | CachedImage does not clear the ImageObserver pointer when dropping its Image ref | - | 2016-10-02 |
| 128458 | Security: NTP Promo data is downloaded via HTTP, but then rendered on the NTP | - | 2016-10-02 |
| 128665 | Heap-use-after-free in WebCore::Node::isInShadowTree | - | 2016-10-02 |
| 128342 | Heap-buffer-overflow in WebCore::SVGUseElement::instanceForShadowTreeElement | - | 2016-10-02 |
| 128336 | Heap-buffer-overflow in WebCore::SubframeLoader::createJavaAppletWidget | - | 2016-10-02 |
| 128256 | tabs permission exploit on the Chrome RSS Extension | - | 2016-10-02 |
| 128204 | Assertion failure (toRenderBox() called on a RenderInline) beneath RenderBlock::blockBeforeWithinSelectionRoot() | - | 2016-10-02 |
| 128178 | Heap-use-after-free in fileapi::FileSystemOperation::DidGetUsageAndQuotaAndRunTask | $3,133 | 2016-10-02 |
| 128163 | Heap-buffer-overflow in GIFImageReader::read | - | 2016-10-02 |
| 128159 | Heap-use-after-free in WTF::HashMap<int, WTF::RefPtr<WebCore::CalculationValue>, WTF::IntHash<unsigned int>, WTF::HashTrait | - | 2016-10-02 |
| 128157 | Heap-use-after-free in WebCore::HTMLFormControlElement::disabled | - | 2016-10-02 |
| 128151 | Heap-use-after-free in WebKit::MainThreadFileSystemCallbacks::didSucceed | - | 2016-10-02 |
| 128146 | UNKNOWN in v8::internal::DescriptorArray::Set | - | 2016-10-02 |
| 128018 | [LangFuzz] Crash in v8::internal::ShortCircuitConsString with invalid read | $1,000 | 2016-10-02 |
| 127889 | Use after free in WebCore::Font::characterRangeCodePath / WebCore::Font::codePath | - | 2016-10-02 |
| 127764 | Heap-use-after-free in WebCore::RenderBlock::xPositionForFloatIncludingMargin | - | 2016-10-02 |
| 127701 | Heap-use-after-free in WebCore::RenderObject::repaint | - | 2016-10-02 |
| 127648 | Out of bounds read in WebCore::Region::Shape::compareShapes | - | 2016-10-02 |
| 127624 | Security: pepper plugins - protect plugin's data files from other plugins and the renderer itself. | - | 2016-10-02 |
| 127525 | Dragging a file into a web renderer exposes the file: scheme | $500 | 2016-10-02 |
| 127522 | Security: Chrome Allows "Carpet Bomb" from File Download | - | 2016-10-02 |
| 127727 | Heap-use-after-free in WebCore::ContextDestructionObserver::contextDestroyed | - | 2016-10-02 |
| 127449 | PPAPI processes hold privileged process handles | - | 2016-10-02 |
| 127418 | Heap-use-after-free in WebCore::SVGTextLayoutEngine::layoutTextOnLineOrPath | $1,000 | 2016-10-02 |
| 127417 | Security: Arbitrary memory read in libxslt | $500 | 2016-10-02 |
| 127371 | Heap-use-after-free in WebCore::AXObjectCache::postNotification | - | 2016-10-02 |
| 127368 | Heap-use-after-free in WebCore::SVGAnimatedLengthAnimator::resetAnimValToBaseVal | - | 2016-10-02 |
| 127367 | Heap-use-after-free in WebCore::ApplyStyleCommand::joinChildTextNodes | - | 2016-10-02 |
| 127366 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::performTrivialReplace | - | 2016-10-02 |
| 127424 | Heap-use-after-free in WebKit::WebPagePopupImpl::closePopup | $1,000 | 2016-10-02 |
| 127234 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::FloatRect>::commitChange | - | 2016-10-02 |
| 126723 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
| 126652 | Heap-buffer-overflow in bool WebCore::Region::Shape::compareShapes<WebCore::Region::Shape::CompareIntersectsOperation> | - | 2016-10-02 |
| 126475 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
| 126414 | [LangFuzz] Crash on heap with invalid read from random address (32 bit) | $500 | 2016-10-02 |
| 126406 | Heap-use-after-free in WebCore::RenderBlock::addChildIgnoringAnonymousColumnBlocks | - | 2016-10-02 |
| 126343 | OOB write in PDF character code mapping | - | 2016-10-02 |
| 126337 | Stack buffer overflow in character range parsing | - | 2016-10-02 |
| 126296 | Security: Browser crash document.createEvent("MouseEvents").initMouseEvent in background tab | $1,000 | 2016-10-02 |
| 125730 | Heap-use-after-free in WebCore::Document::nodeChildrenWillBeRemoved | - | 2016-10-02 |
| 126105 | Global-buffer-overflow in RgnOper::addSpan | - | 2016-10-02 |
| 126074 | Heap-use-after-free in WebCore::SpellChecker::didCheckSucceeded | - | 2016-10-02 |
| 126048 | Heap-use-after-free in SpeechRecognitionManagerImpl::DispatchEvent | $1,000 | 2016-10-02 |
| 126040 | Heap-use-after-free in WebCore::ContainerNode::insertBefore | - | 2016-10-02 |
| 126015 | Heap-use-after-free in WebCore::HTMLFormControlElement::disabled | - | 2016-10-02 |
| 125921 | Heap-buffer-overflow in WebCore::FontCache::releaseFontData | - | 2016-10-02 |
| 125919 | Heap-buffer-overflow in WebCore::SVGAnimatedPointListAnimator::calculateAnimatedValue | $500 | 2016-10-02 |
| 125821 | The Linux setuid sandbox has becomre (even more) insanely complex | - | 2016-10-02 |
| 126075 | Stack-buffer-overflow in SuggestMgr::forgotchar_utf | - | 2016-10-02 |
| 125563 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 125557 | Heap-use-after-free in WebCore::AudioParam::disconnect | - | 2016-10-02 |
| 125555 | Heap-use-after-free in WTF::HashMap<int, WTF::RefPtr<WebCore::CalculationValue>, WTF::IntHash<unsigned int>, WTF::HashTrait | - | 2016-10-02 |
| 125529 | Heap-use-after-free in WebCore::HTMLLinkElement::setCSSStyleSheet | - | 2016-10-02 |
| 125515 | [LangFuzz] Crash on heap with invalid write to random address | $1,000 | 2016-10-02 |
| 108918 | Heap-use-after-free in WebCore::RenderTableSection::rowLogicalHeightChanged | - | 2016-10-02 |
| 108901 | Heap-buffer-overflow in compute_pos_tan | $500 | 2016-10-02 |
| 108894 | Heap-use-after-free in WebCore::HTMLCollection::length | - | 2016-10-02 |
| 108871 | IndexedDB with autoincrement fails on object put and crashes chrome | $1,000 | 2016-10-02 |
| 108605 | Use of uninitialized value in SkAlphaRuns::Break | $1,000 | 2016-10-02 |
| 108798 | Heap-use-after-free in WebCore::(anonymous namespace)::AllowFileSystemMainThreadBridge::signalCompleted | - | 2016-10-02 |
| 108695 | Heap-use-after-free in WebKit::WebFrameImpl::viewImpl | $1,000 | 2016-10-02 |
| 108648 | Security: Malicious extension could avoid being blacklisted via extension blacklist | - | 2016-10-02 |
| 108476 | Heap-buffer-overflow in WebCore::Font::codePath | $500 | 2016-10-02 |
| 108544 | Heap-use-after-free in SubresourceLoader::didFinishLoading | $1,000 | 2016-10-02 |
| 108579 | Heap-buffer-overflow in void WTF::Vector<WTF::RefPtr<WebCore::TextTrack>, 0ul>::insert<WTF::RefPtr<WebCore::TextTrack> > | - | 2016-10-02 |
| 108461 | Heap-use-after-free in WebCore::HTMLInputElement::copyNonAttributeProperties | - | 2016-10-02 |
| 108416 | Global-buffer-overflow in render_line | $500 | 2016-10-02 |
| 108071 | Browser process heap-use-after-free with indexeddb cursors | $3,133 | 2016-10-02 |
| 108037 | Heap-buffer-overflow in WebCore::SVGLength::valueAsString | $1,000 | 2016-10-02 |
| 108006 | Stack-buffer-overflow in HB_MyanmarShape | - | 2016-10-02 |
| 108267 | Heap-use-after-free in WebCore::RenderBlock::selectionGaps | - | 2016-10-02 |
| 108207 | Heap-use-after-free in WebCore::RenderTable::borderBefore | $1,000 | 2016-10-02 |
| 107758 | Heap-use-after-free in WebCore::RenderRegion::offsetFromLogicalTopOfFirstPage | $1,000 | 2016-10-02 |
| 107565 | Security: dragging a file URL between two http-spawned windows goes remote->local | - | 2016-10-02 |
| 107873 | Heap-use-after-free in WebCore::DatabaseTracker::interruptAllDatabasesForContext | - | 2016-10-02 |
| 107616 | UXSS in v8 bindings npCreateV8ScriptObject() | - | 2016-10-02 |
| 107939 | Heap-buffer-overflow in WebCore::RenderBlock::layoutRunsAndFloatsInRange | - | 2016-10-02 |
| 107258 | Freed m_renderer used in InlineBox::deleteLine | - | 2016-10-02 |
| 107244 | Heap-use-after-free in DatabaseObserver | $1,000 | 2016-10-02 |
| 107376 | Memory corruption crash in ExtensionPrefs::MigrateAppIndex. | - | 2016-10-02 |
| 107128 | Heap-buffer-overflow in xmlStringLenDecodeEntities | $4,000 | 2016-10-02 |
| 107277 | Heap-use-after-free in WebCore::RenderTextFragment::willBeDestroyed | - | 2016-10-02 |
| 107182 | Heap use after free with malware blocking page | $3,133 | 2016-10-02 |
| 106672 | Security: Crash in requestAnimationFrame when removing a frame | $1,000 | 2016-10-02 |
| 106671 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 106577 | Heap-buffer-overflow in SkAAClipBlitter::blitAntiH | $500 | 2016-10-02 |
| 107032 | Sad tab when visiting https://code.google.com and --no-displaying-insecure-content | - | 2016-10-02 |
| 106441 | Stack-buffer-overflow in _canonicalize | $1,000 | 2016-10-02 |
| 106419 | Global-buffer-overflow in SkFileDescriptorStream::read | - | 2016-10-02 |
| 106413 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
| 106340 | Heap-use-after-free in WebCore::RenderTable::outerBorderAfter | $3,000 | 2016-10-02 |
| 106336 | Heap-use-after-free in WebCore::CounterNode::insertAfter | $500 | 2016-10-02 |
| 106334 | Security: Popupblocker is ignored, downloads are invisible | - | 2016-10-02 |
| 106484 | Heap-use-after-free in WebCore::RenderObject::childAt | $1,000 | 2016-10-02 |
| 106309 | Heap-buffer-overflow in WebCore::InlineFlowBox::addToLine (regions issue) | - | 2016-10-02 |
| 106165 | Heap-buffer-overflow in safe_browsing protocol parser | - | 2016-10-02 |
| 105867 | Use after free in V8HTMLElementWrapperFactory.cpp | $1,000 | 2016-10-02 |
| 105803 | PDF missing integer validation for Flate / LZW / Fax prediction codes and other parameters | - | 2016-10-02 |
| 106200 | Heap-use-after-free in WebCore::InlineBox::deleteLine | $500 | 2016-10-02 |
| 106316 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::processEndTag | - | 2016-10-02 |
| 105482 | Security: CSP connect-src and script-src not enforced on workers | - | 2016-10-02 |
| 105459 | Use-after frees and bad casts with -webkit-column-span | $2,000 | 2016-10-02 |
| 105714 | Nasty looking INVALID_POINTER_READ in internal PDF-reader | $500 | 2016-10-02 |
| 134123 | Heap-use-after-free in WebCore::VisibleSelection::rootEditableElement | - | 2016-10-02 |
| 105162 | Stack-buffer-overflow in base::files::(anonymous namespace)::InotifyReaderTask::Run | - | 2016-10-02 |
| 134305 | Heap-use-after-free in WebCore::RenderObject::absoluteBoundingBoxRect | - | 2016-10-02 |
| 133725 | Security: public chromium site is leaking internal Google DNS names | - | 2016-10-02 |
| 134088 | Use-after-free: LabelsNodeList isn't updated properly after its owner node is adopted into a new document | - | 2016-10-02 |
| 133892 | Heap-use-after-free in WebCore::RenderListItem::updateMarkerLocation | - | 2016-10-02 |
| 133288 | Heap-buffer-overflow in WebCore::CSPSourceList::parseSource | - | 2016-10-02 |
| 133571 | Heap-use-after-free in SkARGB32_Black_Blitter::blitAntiH | $1,000 | 2016-10-02 |
| 133418 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
| 134101 | Security: webRequest API allows extensions to XSS chrome.google.com and gain access to webstorePrivate API | $2,000 | 2016-10-02 |
| 133214 | UNKNOWN in WebCore::RenderTableSection::addCell | $1,000 | 2016-10-02 |
| 133196 | Heap-use-after-free in WebCore::RenderInline::willBeDestroyed | - | 2016-10-02 |
| 132806 | ChromeContentBrowserClient::AllowSocketAPI using allowed_socket_origins_ without scheme check | - | 2016-10-02 |
| 132779 | Security: WebM heap-buffer-overflow in matroskadec.c:matroska_parse_block() | $1,000 | 2016-10-02 |
| 132699 | Update Java version metadata for Jun 2012 CPU | - | 2016-10-02 |
| 132690 | Heap-use-after-free in WebCore::RenderSVGModelObject::checkIntersection | - | 2016-10-02 |
| 132890 | Crash when using Web Audio + media element with no audio or when user navigates | - | 2016-10-02 |
| 131969 | Heap-use-after-free in WebCore::AccessibilityObject::getAttribute | - | 2016-10-02 |
| 132396 | Heap-use-after-free in WebCore::RenderBlock::layoutRunsAndFloats | - | 2016-10-02 |
| 132398 | Global-buffer-overflow in D_Clear_BitmapXferProc | - | 2016-10-02 |
| 132203 | UAF in ValueStoreFrontend::Backend::Get | - | 2016-10-02 |
| 132019 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 132270 | Global-buffer-overflow in WebCore::mediaControlElementType | - | 2016-10-02 |
| 131968 | Heap-use-after-free in WebCore::AccessibilityTable::isDataTable | - | 2016-10-02 |
| 132241 | Heap-use-after-free in WebCore::DocumentThreadableLoader::cancel | - | 2016-10-02 |
| 131934 | Heap-use-after-free in WTF::Vector<WebCore::Attribute, 0ul>::~Vector | - | 2016-10-02 |
| 131348 | Security: Use-after-free in safe_browseing::DownloadProtectionService found by Valgrind | - | 2016-10-02 |
| 131347 | heap-use-after-free in DictionaryValue while closing chrome, requires extension. | - | 2016-10-02 |
| 131087 | UAF due to Document::removePendingSheet re-entering JavaScript during Document cleanup | - | 2016-10-02 |
| 130927 | Heap-use-after-free in WebCore::CompositeEditCommand::breakOutOfEmptyListItem | - | 2016-10-02 |
| 130824 | Security: Linux crash report generation code reads past the end of an unterminated string buffer. | - | 2016-10-02 |
| 130802 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 0ul>::append<unsigned short> | - | 2016-10-02 |
| 130743 | Chromium is no more asking you for permissions to run WMP plugin via the Infobar. Is it intentional? | - | 2016-10-02 |
| 130723 | Use after free after setting -webkit-line-clamp to none | - | 2016-10-02 |
| 130722 | Heap-use-after-free in WebCore::InsertParagraphSeparatorCommand::doApply | - | 2016-10-02 |
| 130595 | Heap-use-after-free in WebCore::RenderBlock::layoutBlockChildren | $1,000 | 2016-10-02 |
| 130356 | Heap-use-after-free in WebCore::SVGDocumentExtensions::removeAllElementReferencesForTarget | $1,000 | 2016-10-02 |
| 130276 | Chrome attempts to load metro_driver.dll when Metro is not supported | - | 2016-10-02 |
| 130241 | [crash] WebCore::RenderStyle::fontMetrics(void)+0xa | - | 2016-10-02 |
| 130240 | Heap-buffer-overflow WRITE in read_markers third_party/libjpeg_turbo/jdmarker | $1,000 | 2016-10-02 |
| 130237 | Heap-use-after-free in WebCore::RenderObject::arenaDelete | - | 2016-10-02 |
| 130235 | Heap-use-after-free in WebCore::HTMLElement::adjustDirectionalityIfNeededAfterChildrenChanged | - | 2016-10-02 |
| 130369 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | $1,000 | 2016-10-02 |
| 129826 | Chrome_Mac: Zombie <DownloadItemController: 0x1f1e6fd0> received -handleReveal: (via -performSelector:withObject:) | - | 2016-10-02 |
| 129947 | Heap-use-after-free in WebCore::RenderObject::setStyle | $1,000 | 2016-10-02 |
| 129942 | UNKNOWN in v8_i18n::IntlNumberFormat::JSInternalFormat | $1,000 | 2016-10-02 |
| 129936 | Heap-use-after-free in WebCore::InlineTextBox::nodeAtPoint | - | 2016-10-02 |
| 129930 | Security: libxml2 growBuffer integer overflow on 64-bit machines | $3,000 | 2016-10-02 |
| 129898 | Heap-use-after-free in WebCore::CounterNode::lastDescendant | $1,000 | 2016-10-02 |
| 129890 | Heap-use-after-free in WebCore::cancelAll | - | 2016-10-02 |
| 129951 | UNKNOWN in v8::Function::Call | $1,000 | 2016-10-02 |
| 129394 | Heap-use-after-free in WebCore::AccessibilityTable::isDataTable | - | 2016-10-02 |
| 129569 | Heap-use-after-free in WebCore::RenderLayer::updateCompositingLayersAfterScroll | - | 2016-10-02 |
| 129396 | Heap-buffer-overflow in WebCore::RenderTable::colElement | - | 2016-10-02 |
| 129357 | Heap-buffer-overflow in WebCore::RenderProgress::isDeterminate | - | 2016-10-02 |
| 129301 | Heap-use-after-free in WebCore::AXObjectCache::postPlatformNotification | - | 2016-10-02 |
| 129299 | Run-in UAFs part 2 | - | 2016-10-02 |
| 129360 | Heap-use-after-free in WebCore::InlineFlowBox::removeChild | - | 2016-10-02 |
| 105143 | Cross-origin drag-and-drop prevention ineffective | - | 2016-10-02 |
| 105157 | Heap-use-after-free in WebCore::InlineFlowBox::removeChild | - | 2016-10-02 |
| 105133 | Heap-use-after-free in WebCore::RenderObject::isDescendantOf | - | 2016-10-02 |
| 105012 | Global-buffer-overflow in WebCore::RenderFlexibleBox::mainAxisBorderAndPaddingExtentForChild | - | 2016-10-02 |
| 104935 | Security: HSTS "cookies" do not obey expected policy. | - | 2016-10-02 |
| 104863 | Heap-use-after-free in WebCore::SubresourceLoader::didFail | $1,000 | 2016-10-02 |
| 104859 | Heap-use-after-free in WebCore::InlineFlowBox::computeOverAnnotationAdjustment | $1,000 | 2016-10-02 |
| 104617 | Heap-use-after-free in WebCore::CSSImageGeneratorValue::addClient | - | 2016-10-02 |
| 104529 | PDF-reader tab-crash with editable crash address. | $2,000 | 2016-10-02 |
| 104959 | Nasty looking crash on internal pdf-reader | $500 | 2016-10-02 |
| 104461 | Security: chrome://workers/ crash | - | 2016-10-02 |
| 104325 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 104315 | Heap-use-after-free WebCore::RenderObject::container | - | 2016-10-02 |
| 104272 | Security: Directory traversal in extension docs | - | 2016-10-02 |
| 104266 | Heap-use-after-free in WebCore::nextBreakablePosition | - | 2016-10-02 |
| 104466 | Schema check on navigations to chrome/file schemas should be avoided | - | 2016-10-02 |
| 104317 | Stale RenderObject in RenderBlock::addChildIgnoringAnonymousColumnBlocks() | - | 2016-10-02 |
| 104056 | Crash with PDF at bad IP | $1,000 | 2016-10-02 |
| 104223 | Security: MHTML can be used to steal cookies | - | 2016-10-02 |
| 103867 | Security: chrome.test.resetQuota extension API exposed to all extensions | - | 2016-10-02 |
| 103750 | minor self-inflicted xss on chrome://tracking2 | - | 2016-10-02 |
| 103738 | Security: out of bounds array access in WebCore::RenderTableSection::rowLogicalHeightChanged | - | 2016-10-02 |
| 104011 | v8_i18n::BCP47ToICUFormat() - crash | $1,000 | 2016-10-02 |
| 104151 | Bad cast in WebCore::RenderThemeMac::paintMediaToggleClosedCaptionsButton | - | 2016-10-02 |
| 103921 | Use-after-free in DOM Range | $1,000 | 2016-10-02 |
| 103239 | Security: INVALID_POINTER_READ/WRITE_EXPLOITABLE_chrome!SkRgnBuilder::blitH | $1,000 | 2016-10-02 |
| 103259 | [LangFuzz] Crash at v8::internal::WriteQuoteJsonString with invalid write | $1,000 | 2016-10-02 |
| 102810 | Security: buffer overflow in link prefetching | $1,000 | 2016-10-02 |
| 103630 | Security: iFrame SandBox Unique Origin not enforced in extensions | - | 2016-10-02 |
| 103126 | Heap-use-after-free in WebCore::RenderTextFragment::styleDidChange | - | 2016-10-02 |
| 103244 | Pinning checks aren't enforced in the case of a minor error. | - | 2016-10-02 |
| 103058 | Security: missing xslt import causes crash w/preloading | $1,000 | 2016-10-02 |
| 102037 | Security: Use after free in CSSStyleDeclarationInternal::parentRuleAttrGetter | - | 2016-10-02 |
| 101900 | Security: bug rendering web pages with flash content | - | 2016-10-02 |
| 101835 | Exit full screen button crashs browser | - | 2016-10-02 |
| 101779 | OOB read with corrupt PDF; possible stability issue too | - | 2016-10-02 |
| 101624 | Security: buffer overrun leading to heap corruption in ANGLE shader translator | - | 2016-10-02 |
| 102242 | ZDI-CAN-1416: WebKit ContentEditable swapInNode Use-After-Free Remote Code Execution Vulnerability | - | 2016-10-02 |
| 101901 | Security:scrolling web with flash content rendering bug | - | 2016-10-02 |
| 102628 | Security: Adobe regions use-after-free with multiple region css thingies | $1,000 | 2016-10-02 |
| 102461 | Failure to infobar JRE7 | - | 2016-10-02 |
| 102359 | Use-after-free in SVG renderer | $1,000 | 2016-10-02 |
| 101446 | Use after free in TextTrack::~TextTrack | - | 2016-10-02 |
| 101235 | Security: Location bar spoofing when using replaceState in unload event handler | - | 2016-10-02 |
| 101205 | Security: marketplace | - | 2016-10-02 |
| 101172 | Seeking on webm 1080p video causes crash | - | 2016-10-02 |
| 101580 | Heap-use-after-free in WebCore::RenderObject::enclosingLayer | - | 2016-10-02 |
| 101548 | Test: ABCD | - | 2016-10-02 |
| 101494 | OOB read in media::ScaleYUVToRGB32 | - | 2016-10-02 |
| 101458 | OOB read in WebM/vorbis vorbis_decode_frame() | $1,000 | 2016-10-02 |
| 101018 | Use after free in fullscreen unwraprenderer | - | 2016-10-02 |
| 101010 | Security: css/CSSParser.cpp memory corruption bug | - | 2016-10-02 |
| 100958 | Heap-use-after-free WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
| 100879 | Problem with full-screen infobar permission prompt | - | 2016-10-02 |
| 100863 | OOB read in SVG at WebCore::parseArcFlag | - | 2016-10-02 |
| 100543 | OOB read in WebM/vorbis at render_line() | $500 | 2016-10-02 |
| 101065 | Use after free with counters and inline-table and :before content | - | 2016-10-02 |
| 101127 | BlackBerryĂÂź | - | 2016-10-02 |
| 101136 | Security: Search terms hijacked to return only one site for search terms | - | 2016-10-02 |
| 138210 | Information and credential disclosure by file:// URLs (Android) | $500 | 2016-10-02 |
| 138035 | Security: Google Chrome for Android: Current-tab cross-application scripting (UXSS) | $500 | 2016-10-02 |
| 138012 | Heap-buffer-overflow in WebCore::FontCache::releaseFontData | - | 2016-10-02 |
| 137912 | Heap-buffer-overflow in WebCore::DelayDSPKernel::process | - | 2016-10-02 |
| 137891 | Security: HTTPS proxy can run JavaScript on requested HTTPS sites | - | 2016-10-02 |
| 137852 | Heap-use-after-free in WebKit::WebElement::document | - | 2016-10-02 |
| 137778 | Heap-use-after-free in webkit::ppapi::PPB_URLLoader_Impl::FillUserBuffer | - | 2016-10-02 |
| 138208 | Crash in SkGlyphCache::findImage | $1,000 | 2016-10-02 |
| 100492 | Use after free in WebM/matroska at matroska_execute_seekhead() | $3,000 | 2016-10-02 |
| 100465 | OOB read in OGV at unpack_vlcs | $500 | 2016-10-02 |
| 100464 | Use-after-free in WebM at decode_mb_mode | $1,000 | 2016-10-02 |
| 100459 | Use after free in RenderDeprecatedFlexibleBox::layoutHorizontalBox(bool) [and first-letter] | - | 2016-10-02 |
| 100447 | ClusterFuzz Account Check. | - | 2016-10-02 |
| 100322 | Security: Calling arbitrary V8 native functions from JavaScript | - | 2016-10-02 |
| 138196 | Stack-buffer-overflow in NPObjectProxy::NPNEvaluate | - | 2016-10-02 |
| 138192 | Heap-buffer-overflow in WebCore::HTMLInputElement::dataList | - | 2016-10-02 |
| 100526 | Use after free in floats and first-letter | - | 2016-10-02 |
| 137623 | Heap-buffer-overflow in WebPluginDelegateProxy::BackgroundChanged | - | 2016-10-02 |
| 137532 | Security: Android APIs exposed to JavaScript | $500 | 2016-10-02 |
| 137471 | Heap-use-after-free in WebCore::Element::cloneElementWithoutChildren | - | 2016-10-02 |
| 137413 | Heap-buffer-overflow in WebCore::RenderTableSection::setCellLogicalWidths | - | 2016-10-02 |
| 137409 | Heap-use-after-free in WebCore::RenderObject::container | - | 2016-10-02 |
| 137407 | Security: Chrome for iOS security bug | - | 2016-10-02 |
| 137364 | Heap-use-after-free in WebCore::CSSFontSelector::beginLoadTimerFired | - | 2016-10-02 |
| 137707 | Security: Chrome extensions bug cause crash in all Chrome processes | $500 | 2016-10-02 |
| 137671 | Security: Bad cast in WebCore::CalendarPickerElement::hostInput() | $2,000 | 2016-10-02 |
| 137541 | Reproduceable crash. Changing tabs while a specific text field has focus. | - | 2016-10-02 |
| 137233 | Heap-buffer-overflow in WebCore::RenderBlock::handleTrailingSpaces | - | 2016-10-02 |
| 137125 | UNKNOWN in WebCore::StylePropertySet::addParsedProperties | $1,000 | 2016-10-02 |
| 137208 | Security: Mouse lock permission and iframe on different host | - | 2016-10-02 |
| 137174 | UNKNOWN in WebCore::SVGAnimationElement::currentValuesForValuesAnimation | - | 2016-10-02 |
| 137147 | UNKNOWN in WebCore::RenderTable::cellBefore | - | 2016-10-02 |
| 137303 | Corrupted rendering with many MapsGL tabs open | - | 2016-10-02 |
| 137052 | Heap-use-after-free in WebCore::EllipsisBox::paint | - | 2016-10-02 |
| 137363 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
| 137362 | Heap-buffer-overflow in WebCore::CCLayerTreeHostImpl::CullRenderPassesWithNoQuads::shouldRemoveRenderPass | - | 2016-10-02 |
| 137232 | UNKNOWN in WebCore::ElementAttributeData::addAttribute | - | 2016-10-02 |
| 136497 | Security: XSS via Copy&Paste protection bypass using @formaction / General Iframe Sandbox Considerations regarding copy&paste / drag&drop | - | 2016-10-02 |
| 136881 | Security: race condition with workers and sync xmlhttprequests | $500 | 2016-10-02 |
| 136894 | Heap-buffer-overflow in UpsampleBgraLinePairSSE2 | $1,000 | 2016-10-02 |
| 136952 | Heap-use-after-free in WebCore::RenderLineBoxList::dirtyLinesFromChangedChild | - | 2016-10-02 |
| 136226 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
| 136182 | Heap-use-after-free in WebCore::ImageLoader::updateRenderer | - | 2016-10-02 |
| 136344 | Heap-use-after-free in WebCore::FrameLoader::stopAllLoaders | - | 2016-10-02 |
| 136116 | Heap-use-after-free in WebCore::RenderLayer::enclosingFilterLayer | - | 2016-10-02 |
| 136046 | Bad intersection of injected HTTP headers leads to Content Security Policy (CSP) Bypass | - | 2016-10-02 |
| 136296 | Heap-use-after-free in WebCore::SVGSMILElement::resetTargetElement | - | 2016-10-02 |
| 136235 | Heap-use-after-free in WebCore::StyleResolver::collectMatchingRulesForList | $1,000 | 2016-10-02 |
| 136145 | Security: Heap-buffer-overflow on TextFieldDecorationElement::defaultEventHandler | - | 2016-10-02 |
| 135697 | Heap-use-after-free in WebCore::RenderLayer::repaintBlockSelectionGaps | - | 2016-10-02 |
| 135658 | Turn off <iframe> seamless for m21 | - | 2016-10-02 |
| 135595 | Heap-use-after-free in WebCore::ImageLoader::notifyFinished | - | 2016-10-02 |
| 135705 | Heap-buffer-overflow in WebCore::TextIterator::handleTextBox | - | 2016-10-02 |
| 135432 | Heap-buffer-overflow in skia::BGRAConvolve2D | $1,000 | 2016-10-02 |
| 135698 | Heap-use-after-free in WebCore::HTMLInputElement::isPresentationAttribute | - | 2016-10-02 |
| 135485 | SPDY - Pushed stream - crash accessing https://jetty.intalio.com:10111/spdy | - | 2016-10-02 |
| 135071 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::append<unsigned short> | - | 2016-10-02 |
| 134897 | Bad cast with run-ins and <input> | $1,000 | 2016-10-02 |
| 135173 | Heap-use-after-free in WebCore::RenderQuote::rendererRemovedFromTree | - | 2016-10-02 |
| 135043 | Heap-use-after-free in media_stream:: | $3,133 | 2016-10-02 |
| 134429 | Heap-use-after-free in WebCore::Document::clearNodeListCaches | - | 2016-10-02 |
| 134639 | Heap-use-after-free in WebCore::RenderObject::destroyAndCleanupAnonymousWrappers | - | 2016-10-02 |
| 134428 | Heap-buffer-overflow in WebCore::SVGDocumentExtensions::removeAnimationElementFromTarget | - | 2016-10-02 |
| 134519 | Security: memory address disclosure through JavaScript in WebUI's cookies page | - | 2016-10-02 |
| 134402 | Heap buffer overflows in WebCore::CSSParser::lex | - | 2016-10-02 |
| 134324 | Heap-use-after-free in WebCore::RenderBlock::layoutPositionedObjects | - | 2016-10-02 |
| 134325 | Security: Use after free with mouse lock and window.open | $1,000 | 2016-10-02 |
| 100177 | Use after free in first-letter container destruction handling. | - | 2016-10-02 |
| 100149 | Use after free in AX Scrollbars | - | 2016-10-02 |
| 99991 | Use after free in ImageBuffer::toDataURL | - | 2016-10-02 |
| 100059 | Generic fix: Register custom fonts at creation time, rather than retire time. | $1,337 | 2016-10-02 |
| 99652 | OOB read in vp8_decode_frame | $1,000 | 2016-10-02 |
| 99732 | Use after free in table parts. | - | 2016-10-02 |
| 99603 | Use after free due to flexible box not laying some of its children. | - | 2016-10-02 |
| 99597 | Use after free in tables, float, :after content | - | 2016-10-02 |
| 99840 | Windows OpenGL performance drops by 2/3 with GPU sandbox on | - | 2016-10-02 |
| 99880 | Use after free in table :before, :after content. | $1,000 | 2016-10-02 |
| 99901 | BinScope reports SafeSEH not supported on video DLLs | - | 2016-10-02 |
| 99615 | Heap-use-after-free in WebCore::GraphicsContext::paintingDisabled | - | 2016-10-02 |
| 99465 | Security: AccessibilityImageMapLink holds onto it's parent even after it's been freed | - | 2016-10-02 |
| 99348 | Use after free in tables | - | 2016-10-02 |
| 99338 | Use after free in RenderTableSection::splitColumn | - | 2016-10-02 |
| 99596 | Use after free in media::FFmpegDemuxerStream::Read | - | 2016-10-02 |
| 99553 | repeatedly re-setting video.src crashes in WebCore::VideoLayerChromium::updateCompositorResources | - | 2016-10-02 |
| 99480 | OOB read in media::ScaleYUVToRGB32 | - | 2016-10-02 |
| 99294 | Use after free with :after in display table and :first-letter | $1,000 | 2016-10-02 |
| 99167 | [LangFuzz] Crash on Heap involving GC (invalid write) | $1,000 | 2016-10-02 |
| 99104 | WebKit: invalid cast in WebCore::toRenderBlock / WebCore::RenderBlock::blockSelectionGaps | - | 2016-10-02 |
| 99016 | Security: HTTPS Address Bar Spoofing Using View-source And Redirection | $1,000 | 2016-10-02 |
| 99003 | changing proxy | - | 2016-10-02 |
| 99229 | WebKit: Use after free in ~Node because ~HTMLLinkElement triggers script execution | - | 2016-10-02 |
| 99211 | Heap buffer overflow in Webaudio FFTFrame::doFFT | $2,000 | 2016-10-02 |
| 99138 | Use-after-free with plugin and editing | $1,000 | 2016-10-02 |
| 98556 | Use after free with first-letter | $1,000 | 2016-10-02 |
| 98262 | Chrome 16 crash when resizing window | - | 2016-10-02 |
| 98161 | Bug 68816 - Rapidly refreshing a feMorphology[erode] with r=0 can sometimes cause display corruption | - | 2016-10-02 |
| 98773 | [LangFuzz] Crash at v8::Object::SlowGetPointerFromInternalField with invalid read | $1,000 | 2016-10-02 |
| 98809 | Renderer crash with PDF at isalnum | $500 | 2016-10-02 |
| 98582 | Security: invalid memory reference to window object | - | 2016-10-02 |
| 97994 | Use after free due to stale fonts | - | 2016-10-02 |
| 97952 | Stale layout root generic fix from Mitz | - | 2016-10-02 |
| 97898 | Regression: Use after free in RenderBlock::linkToEndLineIfNeeded | - | 2016-10-02 |
| 97867 | Security: Major Google Plus and Google Chrome Problem | - | 2016-10-02 |
| 98089 | memory corruption in ANGLE shader translator | - | 2016-10-02 |
| 98064 | Use-after-free when font is missing | $1,000 | 2016-10-02 |
| 97784 | [v8] Stale pointer in CSSStyleSheet, Invalid cast in V8ListenerList::doFindWrapper | $1,500 | 2016-10-02 |
| 97608 | Use after free in counters in :before, :after content | $500 | 2016-10-02 |
| 97596 | Security: anonymous proxy | - | 2016-10-02 |
| 97553 | Clicking a link on a page that has been fullscreened by JS doesn't exit fullscreen | - | 2016-10-02 |
| 97546 | Use after free in ruby text :after, :before content due to stale styles. | - | 2016-10-02 |
| 97278 | Security: Tracking bug for CachedResourceLoader::canRequest in a redirect chain | - | 2016-10-02 |
| 97148 | Crashes in PhishingDOMFeatureExtractor::ExtractFeaturesWithTimeout | - | 2016-10-02 |
| 97092 | Stale canvas used in WebCore::PlatformContextSkia::save() | $1,000 | 2016-10-02 |
| 97674 | Security: Extension can get at tabs details (url/title) without requesting tabs permission | - | 2016-10-02 |
| 97599 | More stale styles in listmarkers | $1,000 | 2016-10-02 |
| 96747 | Security: Magic iframe transfer vulnerability for Pepper/NaCl plugins | - | 2016-10-02 |
| 96902 | Use-after-free in findPlaceForCounter | $1,000 | 2016-10-02 |
| 97006 | Use after free due to issues in element detachment when entering fullscreen | - | 2016-10-02 |
| 96665 | Use after free in Element::recalcStyle due to reparenting issues in treebuilder | - | 2016-10-02 |
| 96382 | out-of-bounds access in Gradient::sortStopsIfNecessary | - | 2016-10-02 |
| 96292 | Use after free in media BufferedResourceLoader::Start | - | 2016-10-02 |
| 141815 | Heap-use-after-free in WebCore::RenderQuote::detachQuote | - | 2016-10-02 |
| 141651 | Heap-buffer-overflow in SkA8_Blitter::blitAntiH | $500 | 2016-10-02 |
| 141564 | Heap-use-after-free in WebCore::HTMLLinkElement::removedFrom | - | 2016-10-02 |
| 141462 | Extension resources that are not web accessible should not be able to be linked to from the web | - | 2016-10-02 |
| 141444 | Security: Support pinning for Google ccTLDs | - | 2016-10-02 |
| 141395 | UNKNOWN in v8::internal::SemiSpaceIterator::Next | $1,000 | 2016-10-02 |
| 96499 | Heap-use-after-free in WebCore::RenderLayer::updateVisibilityStatus | - | 2016-10-02 |
| 96444 | Freed scrollbar used in RenderScrollbarPart::imageChanged [not related to previous stale m_owner issues] | - | 2016-10-02 |
| 96149 | Use after free in WebCore::AudioChannel::sumFrom | - | 2016-10-02 |
| 141093 | Security: Dev only restriction for declarativeWebRequest does not seem to work | - | 2016-10-02 |
| 96150 | Use after free in OfflineAudioDestinationNode::notifyCompleteDispatch | - | 2016-10-02 |
| 140805 | Heap-use-after-free in WebCore::RenderRegion::restoreRegionObjectsOriginalStyle | - | 2016-10-02 |
| 140803 | Heap-buffer-overflow in SkA8_Blitter::blitH | $1,000 | 2016-10-02 |
| 140720 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
| 140656 | Heap-use-after-free in WebCore::CachedResource::didAddClient | $1,000 | 2016-10-02 |
| 140647 | UNKNOWN in ogg_calc_pts | - | 2016-10-02 |
| 140642 | Heap-buffer-overflow in SkDashPathEffect::SkDashPathEffect | - | 2016-10-02 |
| 96131 | Closing parent then child in gmail = sad tab | - | 2016-10-02 |
| 96170 | Use after free in InspectorPageAgent::resourceContent | - | 2016-10-02 |
| 140495 | Text box fails to render contents and does not accept user input. | - | 2016-10-02 |
| 140484 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 140368 | Security: heap-use-after-free in xsltGenerateIdFunction | - | 2016-10-02 |
| 140165 | Heap-buffer-overflow in vorbis_decode_frame | - | 2016-10-02 |
| 140142 | Heap-use-after-free in base::internal::WeakReference::is_valid | - | 2016-10-02 |
| 140532 | Heap-use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 140544 | Security: CSP doesn't turn off eval, etc. in Web Workers | - | 2016-10-02 |
| 140083 | [LangFuzz] Crash on heap trying to execute address 0x0000000200000000. | $1,000 | 2016-10-02 |
| 140045 | REGRESSION(r122498): Assertion failure: m_nodeListCounts is sometimes not zero in the Document destructor | - | 2016-10-02 |
| 139961 | Heap-use-after-free in WebCore::TargetListener::handleEvent [Stale target] | - | 2016-10-02 |
| 139814 | UAF in DOMContentLoaded | $2,000 | 2016-10-02 |
| 139789 | Heap-buffer-overflow in WebCore::CSSParser::updateLastSelectorLineAndPosition | - | 2016-10-02 |
| 139772 | AddressSanitizer reports a global buffer underflow in swizzle_for_size() in Mesa | - | 2016-10-02 |
| 139744 | Security: SSL compression infoleak | $5,337 | 2016-10-02 |
| 140085 | UNKNOWN in /mnt/scratch0/clusterfuzz/slave-bot/builds/revisions/asan-linux-release-149416/chrome+Unknown | - | 2016-10-02 |
| 139685 | OOB read atleast in WebCore::SVGListProperty<WebCore::SVGTransformList>::getItemValuesAndWrappers | - | 2016-10-02 |
| 139690 | Heap-use-after-free in WebCore::GenericEventQueue::timerFired | - | 2016-10-02 |
| 139646 | Heap-use-after-free in WebCore::DynamicNodeList::itemWithName | - | 2016-10-02 |
| 139679 | Bad cast in RenderFrameSet::computeEdgeInfo | - | 2016-10-02 |
| 139530 | Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
| 139475 | Heap-use-after-free in WebCore::TargetListener::handleEvent [Stale event listener] | - | 2016-10-02 |
| 139462 | Heap-use-after-free in SkCanvas::updateDeviceCMCache | - | 2016-10-02 |
| 139541 | UNKNOWN in v8::HandleScope::CreateHandle | - | 2016-10-02 |
| 139464 | Heap-use-after-free in WebCore::RenderSVGShape::calculateStrokeBoundingBox | - | 2016-10-02 |
| 139321 | Heap-use-after-free in WebCore::InlineBox::extractLine | - | 2016-10-02 |
| 139402 | Heap-use-after-free in D_Clear_BitmapXferProc | - | 2016-10-02 |
| 139215 | Heap-use-after-free in WebCore::StyleResolver::collectMatchingRules | - | 2016-10-02 |
| 139168 | Security: Creating a loop in the DOM tree (99% a DoS) | $500 | 2016-10-02 |
| 139131 | Heap-use-after-free in WebCore::StyleResolver::collectMatchingRulesForList | - | 2016-10-02 |
| 139290 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImage | - | 2016-10-02 |
| 139383 | Heap-use-after-free in WebCore::HTMLTextFormControlElement::fixPlaceholderRenderer | - | 2016-10-02 |
| 139240 | Heap-buffer-overflow in WebCore::TextTrackCueList::add | - | 2016-10-02 |
| 138738 | Crash in extensions::SetContentSettingFunction | - | 2016-10-02 |
| 138915 | Heap-use-after-free in WebCore::ContainerNode::cloneChildNodes | - | 2016-10-02 |
| 138422 | Heap-use-after-free in WebCore::Font::glyphDataAndPageForCharacter | - | 2016-10-02 |
| 138404 | Heap-use-after-free in WebCore::Document::page | - | 2016-10-02 |
| 138673 | Heap-buffer-overflow in xsltApplyTemplates | $1,000 | 2016-10-02 |
| 138990 | Heap-use-after-free in WebCore::SVGStyledElement::clearHasPendingResourcesIfPossible | - | 2016-10-02 |
| 138672 | Heap-double-free in xsltCompileStepPattern | - | 2016-10-02 |
| 138901 | Heap-use-after-free in ProfileKeyedBaseFactory::GetProfileToUse | - | 2016-10-02 |
| 138302 | Stack-buffer-overflow in NPObjectProxy::NPInvokePrivate | - | 2016-10-02 |
| 138318 | UXSS with pointer lock | - | 2016-10-02 |
| 138382 | Heap-use-after-free in WebCore::AutoTableLayout::recalcColumn | - | 2016-10-02 |
| 138316 | Heap-use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 95849 | Security: any Chrome committer (or parhaps even any user with Google account?) can compromise Google Chrome | - | 2016-10-02 |
| 95842 | Security: Chrome Gives Unreliable Security Info | - | 2016-10-02 |
| 95761 | Use after free in ContainerNode::removeChild (looks related to plugin) | - | 2016-10-02 |
| 95672 | Use after free in ListIterms and RunIns rendering (from bug 88680) | $1,000 | 2016-10-02 |
| 95669 | Regression(r93913): Use after free in ScriptController::executeScript | - | 2016-10-02 |
| 95992 | Security: header injection when using embeded \0 in headerline | - | 2016-10-02 |
| 95920 | [LangFuzz] Crash at v8::internal::ElementsAccessorBase with invalid read | $1,000 | 2016-10-02 |
| 95917 | Security: Chrome does not ask for approval when "not trusted" SSL cert. changes | - | 2016-10-02 |
| 95563 | OOB read in tibetan_nextSyllableBoundary | - | 2016-10-02 |
| 95625 | OOB read in gpu::gles2::GLES2DecoderImpl::HandleDrawArrays | - | 2016-10-02 |
| 95499 | Use after free due to style not updated and having stale fonts. | - | 2016-10-02 |
| 95485 | [LangFuzz] Crash at v8::internal::Object::Lookup | $1,000 | 2016-10-02 |
| 95639 | Use after free in Document::fullScreenChangeDelayTimerFired | - | 2016-10-02 |
| 95620 | use-after-free in browser_tests | - | 2016-10-02 |
| 95520 | Child not placed correctly when :before, :after placed in same table part container causing stale style | - | 2016-10-02 |
| 95359 | Use after free in WebCore::SVGTRefElement::updateReferencedText | - | 2016-10-02 |
| 95360 | use after free in WebCore::ContainerNode::removeChild via Range.deleteContents() | - | 2016-10-02 |
| 95083 | Security: Reveal stored passwords using the Developer Tool | - | 2016-10-02 |
| 95072 | Use after free due to style not updated for svg text runs. | $1,000 | 2016-10-02 |
| 95012 | Add defensive bounds checking in AudioNode | - | 2016-10-02 |
| 94834 | Security: Thread safety with AudioChannelMerger | - | 2016-10-02 |
| 95374 | Redirect to chrome:// URIs via Location: header | $2,337 | 2016-10-02 |
| 95465 | 4 OOB reads in XMLDocumentParser::doWrite | - | 2016-10-02 |
| 95333 | ERROR:the following pages have become unresponsive. you can wait to become responsive or kill them | - | 2016-10-02 |
| 94820 | Don't allow nodes of one context to be connected to nodes of another context | - | 2016-10-02 |
| 94743 | Regression(r93913): Use after free in ScheduledAction::execute(WebCore::V8Proxy*) | - | 2016-10-02 |
| 94578 | Security: Brute forcing Intranet WWW-Auth with script element | - | 2016-10-02 |
| 94487 | Security: JSC::Yarr regexp 32/48 to the left of 768 with workers | $1,000 | 2016-10-02 |
| 94464 | Security: e | - | 2016-10-02 |
| 94463 | Security: e | - | 2016-10-02 |
| 94462 | Security: e | - | 2016-10-02 |
| 94461 | Security: e | - | 2016-10-02 |
| 94460 | Security: e | - | 2016-10-02 |
| 94459 | Security: e | - | 2016-10-02 |
| 94458 | Security: e | - | 2016-10-02 |
| 94810 | Use after free with Floats and Ruby | - | 2016-10-02 |
| 94809 | Use after free in ruby overhang. | - | 2016-10-02 |
| 94456 | Security: | - | 2016-10-02 |
| 94275 | Make sure that AudioArray is 16-byte aligned | - | 2016-10-02 |
| 94273 | V8 custom bindings for AudioNode must do proper object checking and throw exception in case of error | - | 2016-10-02 |
| 94186 | WebAudio node lifetype crash when tearing down audio nodes / media element node | - | 2016-10-02 |
| 94025 | WebAudio: Integer overflows in AudioArray | - | 2016-10-02 |
| 93978 | Out of bounds reads and writes when FFT size is changed. | - | 2016-10-02 |
| 93918 | Regression(93122): Use after free in InspectorCSSAgent::clearFrontend | - | 2016-10-02 |
| 94457 | Security: e | - | 2016-10-02 |
| 94278 | Fix thread-safety of AudioNode deletion | - | 2016-10-02 |
| 93596 | Bad read in bundled PDF viewer | - | 2016-10-02 |
| 93497 | Security: Accessibility of the chrome.webstorePrivate-API | - | 2016-10-02 |
| 93472 | Yet another double-free caused by malformed XPath expression in XSLT | $1,000 | 2016-10-02 |
| 93420 | Use after free in FocusController::advanceFocusInDocumentOrder | $1,000 | 2016-10-02 |
| 93788 | Use after free in RenderText lineboxes. | $1,000 | 2016-10-02 |
| 93587 | Use after free in WebCore::Text::recalcStyle due to before after content issue in table parts | $1,000 | 2016-10-02 |
| 93856 | Use after free in RenderFlowThread::nextRendererForNode | - | 2016-10-02 |
| 93146 | Security: Possible race condition in Windows Policy reading that can lead to stale policy. | - | 2016-10-02 |
| 93106 | Failing assertion in IDBTransaction.cpp | - | 2016-10-02 |
| 93097 | Defensively null out danging pointers in the NaCl browser plugin memory safety for M14 | - | 2016-10-02 |
| 93059 | OOB read in EventDispatcher::adjustToShadowBoundaries | - | 2016-10-02 |
| 93416 | Security: Arbitrary cross-origin bypass using __defineGetter__ prototype override | $2,000 | 2016-10-02 |
| 93236 | Stale Pointer Crash in PrintWebViewHelper::PrintPreviewContext::CreatePreviewDocument | - | 2016-10-02 |
| 92959 | Stale node in StyleSheetCandidateListHashSet | $1,000 | 2016-10-02 |
| 92769 | Use after free in TreeBuilder | - | 2016-10-02 |
| 92651 | Use after free due to style not updated for ANONYMOUS boxes (e.g RenderRow), inline-blocks (e.g. RenderRubyRun) | $1,000 | 2016-10-02 |
| 92621 | Use after free in VisibleSelection::selectionFromContentsOfNode | - | 2016-10-02 |
| 92550 | Chrome (main process) crashes when setVersion is called when all (Indexed) database name space is used up | - | 2016-10-02 |
| 92226 | Use after free in CounterNode::lastDescendant | - | 2016-10-02 |
| 92840 | Use after free in HarfbuzzFace::~HarfbuzzFace | - | 2016-10-02 |
| 146433 | Chrome_Mac: Crash Report - base::::CrMallocErrorBreak / invalid free in SkWriter32::rewindToOffset | - | 2016-10-02 |
| 146235 | WTF::equal is too aggressive and may trigger ASan reports | - | 2016-10-02 |
| 146208 | Heap-buffer-overflow in WebCore::RenderTableSection::nodeAtPoint | - | 2016-10-02 |
| 146145 | Heap-use-after-free in WebCore::RenderText::computePreferredLogicalWidths | - | 2016-10-02 |
| 146144 | Heap-use-after-free in WebCore::FrameView::scrollContentsFastPath | - | 2016-10-02 |
| 146111 | Heap-use-after-free in WebCore::RenderBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 145976 | Heap-use-after-free in WebCore::HTMLTextFormControlElement::fixPlaceholderRenderer | - | 2016-10-02 |
| 145921 | AddressSanitizer reports a UAF in WebCore::RenderStyle::letterSpacing | - | 2016-10-02 |
| 146146 | Heap-buffer-overflow in WebCore::FlowThreadController::unregisterNamedFlowContentNode | - | 2016-10-02 |
| 145867 | Heap-use-after-free in WebCore::FrameView::scrollContentsFastPath | - | 2016-10-02 |
| 145915 | Security/Privacy: <img>-embedded SVG will load external content referenced by CSS @import @font-face | - | 2016-10-02 |
| 145530 | Mitigation: Kill OOB reads(or few writes) by preventing access to harmful locals in dirty text lineboxes | - | 2016-10-02 |
| 145525 | Security: heap buffer overflow in gpu process with webgl | $3,500 | 2016-10-02 |
| 145492 | Web Inspector: Page with @import and :last-child in an edited stylesheet will crash (UAF) | - | 2016-10-02 |
| 145544 | Security: integer overflow in gpu process with webgl | $1,000 | 2016-10-02 |
| 145272 | Heap-use-after-free in WebCore::nextBreakablePosition | - | 2016-10-02 |
| 145018 | Heap-use-after-free in WebCore::StyleSheetContents::checkLoadCompleted | - | 2016-10-02 |
| 144886 | Security: webgl crash on mesa | $3,133 | 2016-10-02 |
| 144866 | Security: Chrome for Android Bypassing SOP for Local Files By Symlinks | $500 | 2016-10-02 |
| 144831 | Heap-buffer-overflow in WebCore::StylePropertySet::copyPropertiesFrom | - | 2016-10-02 |
| 145363 | Security: Chrome extension DEP crash | - | 2016-10-02 |
| 144899 | SkPaint::SkPaint - crash | $1,000 | 2016-10-02 |
| 144799 | Heap-double-free in xmlFreeNodeList | - | 2016-10-02 |
| 144813 | Security: UXSS via com.android.browser.application_id Intent extra | $500 | 2016-10-02 |
| 144671 | Heap-use-after-free in WebCore::GCPrologueVisitor<void, WebCore::SpecialCasePrologueObjectHandler>::visitDOMWrapper | - | 2016-10-02 |
| 144466 | Crash when verifying ECDSA certificate on XP | - | 2016-10-02 |
| 144734 | Heap-buffer-overflow in WebCore::RenderTable::removeCaption | - | 2016-10-02 |
| 144810 | Heap-use-after-free in WebCore::RenderTable::calcBorderEnd | - | 2016-10-02 |
| 144704 | Tracking bug for fixing rel=noreferrer aslr bypass | - | 2016-10-02 |
| 143761 | Heap-use-after-free in WebCore::GraphicsContext::restore | $1,000 | 2016-10-02 |
| 143672 | Flapper Crash in BrokerProcessDispatcher::GetSitesWithData | - | 2016-10-02 |
| 143859 | Security: World-writable shared memory segments for X/Linux UI | - | 2016-10-02 |
| 144051 | Security: Memory address disclosure through JavaScript in Print Preview WebUI | - | 2016-10-02 |
| 143846 | Security: Chromoting creates a world-writable shared memory segment | - | 2016-10-02 |
| 143609 | Heap-use-after-free in WebCore::ElementV8Internal::onclickAttrGetter | $1,000 | 2016-10-02 |
| 143604 | Heap-use-after-free in WebCore::RenderBlock::LineBreaker::nextLineBreak [SVG text] | - | 2016-10-02 |
| 143593 | Heap-buffer-overflow in WebCore::SurrogatePairAwareTextIterator::consume | - | 2016-10-02 |
| 143582 | Heap-use-after-free in WTF::OwnPtr<WTF::Vector<WebCore::RegisteredEventListener, 1ul> >::~OwnPtr | - | 2016-10-02 |
| 143551 | Heap-use-after-free in WebCore::TreeScopeAdopter::moveTreeToNewScope | - | 2016-10-02 |
| 143656 | Heap-use-after-free in WebCore::SVGTRefElement::updateReferencedText | $1,000 | 2016-10-02 |
| 143648 | Heap-buffer-overflow in WebCore::StyleResolver::applyProperty | - | 2016-10-02 |
| 143176 | Heap-use-after-free in WebCore::AccessibilityNodeObject::document | - | 2016-10-02 |
| 143409 | Heap-buffer-overflow in SkScalerContext_FreeType::generateImage | - | 2016-10-02 |
| 142956 | Security: XSS in SSL Certificate error page | $500 | 2016-10-02 |
| 142876 | Heap-buffer-overflow in WebCore::HarfBuzzShaperBase::isWordEnd | - | 2016-10-02 |
| 143329 | Bad cast in RenderGrid::layoutGridItems | - | 2016-10-02 |
| 143004 | Security: Untrustworthy Chrome OS user-wallpaper png's are loaded pre-login (in the sandboxed utility process) | - | 2016-10-02 |
| 142310 | ASan reports a use-after-free in IndexedDBBrowserTest.Bug109187Test | - | 2016-10-02 |
| 142395 | Bad cast in computeReplacedLogicalHeightUsing | - | 2016-10-02 |
| 142145 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
| 142746 | Security: Potential use after destruction in ui/gfx/image | - | 2016-10-02 |
| 142169 | Heap-buffer-overflow in SkAlphaRuns::add | $500 | 2016-10-02 |
| 142088 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 142087 | UNKNOWN in void v8::internal::String::WriteToFlat<char> | - | 2016-10-02 |
| 141901 | Security: mesa stack scribbling thingamadoo | $3,133 | 2016-10-02 |
| 141889 | Security: Cookie theft from Chrome by malicious Android app | $500 | 2016-10-02 |
| 91972 | Regression(85705): Use after free on m_originatingLine in floats | - | 2016-10-02 |
| 91940 | Security: Romanian colloquialism meaning penis when viewing YouTube channels | - | 2016-10-02 |
| 91939 | Security: Romanian colloquialism meaning penis when viewing YouTube channels | - | 2016-10-02 |
| 91921 | Use after free in RenderRubyBase | - | 2016-10-02 |
| 91911 | Freed m_renderer used in InlineBox::deleteLine | - | 2016-10-02 |
| 91973 | Regression(90971): Use after free in Textarea placeholder | - | 2016-10-02 |
| 91665 | Crash on bad rip when opening a PDF | $1,000 | 2016-10-02 |
| 91801 | Use after free of RootInlineBox | - | 2016-10-02 |
| 91577 | file:// URL access is defaulting to opt-in | - | 2016-10-02 |
| 91554 | Possible use-after-free in AddToConsole | - | 2016-10-02 |
| 91633 | Security: When upgrade to 13.0.782.107, chrome will run js and load image which had be disabled in chrome | - | 2016-10-02 |
| 91502 | Security: Malware Page forbids user from closing a tab.(window.onunload hijack) | - | 2016-10-02 |
| 91362 | Regression(91331): Bad cast due to html renderer created for svg glyphref | - | 2016-10-02 |
| 91312 | Security: Native Client app can crash trusted code. | - | 2016-10-02 |
| 91218 | XSS in chrome://appcache-internals | - | 2016-10-02 |
| 91517 | Security: V8 asserts (crashes) when entering simple JS snippit | - | 2016-10-02 |
| 91321 | Regression(91788): Bad cast in WebCore::blockWithNextLineBox | - | 2016-10-02 |
| 91020 | Use after free in MediaTest.FLAKY_VideoBearWebm on Mac OS | - | 2016-10-02 |
| 91099 | OOB read in RenderScrollbarPart::computeScrollbarWidth | - | 2016-10-02 |
| 91120 | [LangFuzz] Crash at Runtime_QuoteJSONString with invalid write | $500 | 2016-10-02 |
| 91082 | Security: Major Privacy Loop Hole ! | - | 2016-10-02 |
| 91079 | where to submit Google account bug | - | 2016-10-02 |
| 91093 | Bad cast in paintMediaPlayButton | - | 2016-10-02 |
| 91016 | Security: Canvas toDataURL security error: It is taking page information and not the canvas when making the image | $500 | 2016-10-02 |
| 91013 | [LangFuzz] Crash at RootMarkingVisitor::VisitPointers (32 bit) | $1,000 | 2016-10-02 |
| 91010 | [LangFuzz] Crash at JSObject::SetDictionaryElement with invalid read (32 bit) | $1,000 | 2016-10-02 |
| 91197 | Use after free or bad cast with empty .swf file | - | 2016-10-02 |
| 91092 | Use after free in SVGUseElement::buildShadowTree | - | 2016-10-02 |
| 90978 | read out of bounds in sUnpremultiplyData_RGBA8888 / ImageBufferData::getData (WEBKIT 65352) | - | 2016-10-02 |
| 90668 | Use after free in WebCore::findPlainText | $1,000 | 2016-10-02 |
| 90498 | Security: automatically downloading of .crdownload-files | - | 2016-10-02 |
| 91008 | [LangFuzz] Crash at JSObject::PrepareElementsForSort with invalid read | $1,000 | 2016-10-02 |
| 90357 | OOB read in WebCore::previousBoundary | - | 2016-10-02 |
| 90217 | Prevent silent truncation of trailing characters in downloaded file names | - | 2016-10-02 |
| 90173 | OOB read in media::ScaleYUVToRGB32 due to failure to account for zero source width and accessing negative indices | - | 2016-10-02 |
| 90134 | OOB read in harfbuzz with khmer character | - | 2016-10-02 |
| 90105 | Heap-buffer-overflow in WebCore::RenderBlock::LineBreaker::nextLineBreak | - | 2016-10-02 |
| 89991 | Regression(82144): OOB InlineIterator read in TrailingObjects::updateMidpointsForTrailingBoxes | $500 | 2016-10-02 |
| 90175 | Security: remove any site from Google Index | - | 2016-10-02 |
| 89795 | Browser crash in net::WebSocketJob::SendPending | - | 2016-10-02 |
| 89580 | Use after free due to continuation splitting issues in -webkit-column-span | - | 2016-10-02 |
| 89599 | Freed SVGTRefElement used in SVGStyledElement::buildPendingResourcesIfNeeded | - | 2016-10-02 |
| 89836 | Tracking bug for ANGLE memory corruption on Windows | $1,337 | 2016-10-02 |
| 89575 | Use after free of markers in CompositeEditCommand::replaceTextInNodePreservingMarkers | - | 2016-10-02 |
| 89564 | Possible URL Bar Spoofing when history.forward() is ignored using forward button | $500 | 2016-10-02 |
| 89678 | Use after free in ReplacementFragment::removeUnrenderedNodes | - | 2016-10-02 |
| 89552 | Use after free in CSSStyleSheet::checkLoaded | - | 2016-10-02 |
| 89522 | SVG animation API crashes on SVGAnimateTransform | - | 2016-10-02 |
| 89511 | Use after free in IDBRequest::abort | - | 2016-10-02 |
| 89493 | Use after free in SVG foreignobject rendering. | - | 2016-10-02 |
| 89422 | Two use after frees in NPObjectStub | - | 2016-10-02 |
| 89558 | Use after free in SVGUseElement::buildShadowTree | $500 | 2016-10-02 |
| 89402 | Memory corruption (double free) caused by malformed XPath expression in XSLT | $1,000 | 2016-10-02 |
| 89330 | DocumentLoader use after free in KURL::strippedForUseAsReferrer | $1,000 | 2016-10-02 |
| 89219 | Use after free due to document destruction within unload event | $1,000 | 2016-10-02 |
| 89142 | PDF viewer crash | $500 | 2016-10-02 |
| 89020 | Security: ftp | - | 2016-10-02 |
| 88976 | possible use after free WebCore::FontCache::getFontDataForCharacters | - | 2016-10-02 |
| 88949 | Security: Location Bar Spoofing using very long string on a web address in the location bar | - | 2016-10-02 |
| 88944 | Use-after free in leveldb | $3,133 | 2016-10-02 |
| 88932 | Security: Exploit in google+ | - | 2016-10-02 |
| 152691 | chrome!std::_Tree<std::_Tmap_traits<tracked_objects::Location,tracked_objects::Births *,std::less<tracked_objects::Location>,std::allocator<std::pair<tracked_objects::Location const ,tracked_objects::Births *> >,0> >::find+15 - crash | $2,000 | 2016-10-02 |
| 152585 | Heap-use-after-free in WebCore::ContainerNode::removeAllChildren | - | 2016-10-02 |
| 152420 | Heap-use-after-free in content::P2PSocketClient::OnDataReceived | - | 2016-10-02 |
| 152354 | Mask RenderArena freelist entries. | - | 2016-10-02 |
| 152569 | Chrome_Mac: Crash Report - Stack Signature: CompositorOutputSurface::OnMessageReceived-... | $500 | 2016-10-02 |
| 152442 | Heap-use-after-free in icu_46::RuleBasedCollator::RuleBasedCollator | - | 2016-10-02 |
| 151895 | Defense to throw "unauthorized" infobar for excessively crashing plug-in does not work for Pepper Flash! | - | 2016-10-02 |
| 151888 | Crash in v8::internal::SlotsBuffer::UpdateSlotsRecordedIn | - | 2016-10-02 |
| 151854 | Heap-use-after-free in WebCore::CachedResource::addClientToSet | - | 2016-10-02 |
| 151795 | Security: remove chrome.experimental.offscreenTabs API | - | 2016-10-02 |
| 152104 | out of bounds array access in WTF::TypedArrayBase<unsigned char>::item(unsigned int) / WebCore::FEMorphology::platformApplyGeneric | - | 2016-10-02 |
| 151992 | Heap-use-after-free in VideoCaptureImpl::RemoveClient | - | 2016-10-02 |
| 151860 | Heap-use-after-free in WebCore::DateTimeFieldElement::didBlur | $1,000 | 2016-10-02 |
| 151008 | Heap-use-after-free in WebCore::CanvasRenderingContext2D::setFont | $1,000 | 2016-10-02 |
| 151424 | Chrome: Crash Report - Stack Signature: WebCore::CachedImage::likelyToBeUsedSoon()-... | - | 2016-10-02 |
| 151449 | Heap-buffer-overflow in cc::CCKeyframedTransformAnimationCurve::getValue | - | 2016-10-02 |
| 150966 | Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
| 151049 | Heap-use-after-free in WebCore::RenderObject::destroyAndCleanupAnonymousWrappers | - | 2016-10-02 |
| 150571 | Global-buffer-overflow in v128_copy_octet_string | - | 2016-10-02 |
| 150067 | Heap-buffer-overflow in WebCore::InlineFlowBox::placeBoxesInInlineDirection | - | 2016-10-02 |
| 149999 | Heap-use-after-free in WebCore::WebKitCSSSVGDocumentValue::load | - | 2016-10-02 |
| 150842 | Heap-use-after-free in content::P2PSocketClient::DeliverOnSocketCreated | - | 2016-10-02 |
| 150545 | UNKNOWN in v8::internal::RootMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
| 150650 | MSI installer ships an out-of-date GoogleUpdate.exe with no ASLR or DEP (and may not be updating) | - | 2016-10-02 |
| 150729 | UNKNOWN in v8::internal::Invoke | $1,500 | 2016-10-02 |
| 150737 | IndexedDB causes V8 heap corruption | $1,000 | 2016-10-02 |
| 149717 | Security: integer overflow in webgl on osx | $1,000 | 2016-10-02 |
| 149877 | Security: Omnibox drop target enables navigation to restricted URLs | - | 2016-10-02 |
| 149904 | Security: webgl - after running out of memory, buffer can still be written | $1,000 | 2016-10-02 |
| 149840 | Heap-use-after-free in WebCore::StyleRuleImport::setCSSStyleSheet | - | 2016-10-02 |
| 149871 | Untrustworthy navigation causes HTTP Basic Auth dialog origin confusion/spoofing | - | 2016-10-02 |
| 148612 | Heap-use-after-free in WebCore::pushFullyClippedState | - | 2016-10-02 |
| 148896 | UNKNOWN in v8::internal::ElementsAccessorBase<v8::internal::ExternalUnsignedByteElementsAccessor, v8::internal: | - | 2016-10-02 |
| 148378 | [LangFuzz] Crash due to invalid free in v8::internal::Runtime_RegExpExecMultiple | $1,000 | 2016-10-02 |
| 148692 | Heap-buffer-overflow in ucstrTextExtract | $500 | 2016-10-02 |
| 148638 | Heap-buffer-overflow in SkAAClipBlitter::blitAntiH | $500 | 2016-10-02 |
| 148567 | Touch events allow cross-origin access | $500 | 2016-10-02 |
| 147625 | Security: UXSS/SOP bypass with document.write (Chrome on iOS) | $500 | 2016-10-02 |
| 147499 | Heap-use-after-free in media::AudioOutputDevice::AudioThreadCallback::Process | $3,133 | 2016-10-02 |
| 147475 | UNKNOWN in v8::internal::Deoptimizer::DoComputeOutputFrames | - | 2016-10-02 |
| 147459 | Heap-use-after-free in WebCore::ImageLoader::updateRenderer | - | 2016-10-02 |
| 148376 | [LangFuzz] Crash at v8::internal::MarkCompactCollector::EvacuateNewSpace with invalid read | $1,000 | 2016-10-02 |
| 147700 | Heap-use-after-free in WebCore::Document::fullScreenChangeDelayTimerFired | - | 2016-10-02 |
| 147592 | Chrome_ChromeOS: Crash Report - Stack Signature: WebKit::WebWorkerClientImpl::openFileSystem... | - | 2016-10-02 |
| 146882 | Heap-use-after-free in WebCore::InlineBox::adjustPosition | - | 2016-10-02 |
| 146760 | Security: URL bar spoofing with SSL error messages (Chrome on iOS) | $500 | 2016-10-02 |
| 146725 | AddressSanitizer reports a use-after-free in WebKit::DateTimeChooserImpl::didClosePopup | - | 2016-10-02 |
| 147435 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
| 147436 | UNKNOWN in sk_memset32_SSE2 | - | 2016-10-02 |
| 147290 | Heap-use-after-free in WebCore::DateTimeEditElement::setEmptyValue | $1,000 | 2016-10-02 |
| 146492 | Check behavior of "," in "content_security_policy" manifest attribute. | - | 2016-10-02 |
| 88850 | Use after free with fuzzed ogv file | $1,000 | 2016-10-02 |
| 88846 | Use-after-free in FrameLoader with no form post method | $1,000 | 2016-10-02 |
| 88889 | Stale pointer due to floats not removed (flexible box display) | $1,000 | 2016-10-02 |
| 88858 | [LangFuzz] Crash at JSObject::LocalLookupRealNamedProperty with invalid read on gc | $1,000 | 2016-10-02 |
| 88757 | AudioContext GainNode memory corruption | - | 2016-10-02 |
| 88730 | Use after free in SVGUseElement::invalidateShadowTree / SVGElementInstance::invalidateAllInstancesOfElement | - | 2016-10-02 |
| 88723 | REGRESSION (r85964): Use after free in WebCore::RenderObject::localToAbsolute | - | 2016-10-02 |
| 88684 | Stale m_owner in RenderScrollbar (m_owner is deleted body element) | - | 2016-10-02 |
| 88670 | ZDI-CAN-1283: Webkit fontface Invalid Font Family Remote Code Execution Vulnerability | - | 2016-10-02 |
| 88649 | HRTFDatabaseLoader memory corruption | - | 2016-10-02 |
| 88647 | webkitAudioContext can be called as a function instead of a constructor. | - | 2016-10-02 |
| 88827 | OOB read due to Integer overflow in SkDashPathEffect constructor (len and phase) | - | 2016-10-02 |
| 88729 | Security: PPB_Graphics2D_Create will lead to integer overflow in shm alloc | - | 2016-10-02 |
| 88436 | Ogg memory corruption | - | 2016-10-02 |
| 88337 | The beforeload event allows tracking URI changes in a frame | $500 | 2016-10-02 |
| 88131 | Aw, Snap! with context.createBuffer(request.response, false) on certain files | - | 2016-10-02 |
| 88093 | Security: out-of-bounds read in v8 with defineProperty and arguments | $1,000 | 2016-10-02 |
| 88591 | [LangFuzz] CHECK(!value->IsTheHole()) failed // Crash with invalid read in shell | $1,000 | 2016-10-02 |
| 88531 | Use-after-free in SafeBrowsingResourceHandler::OnBrowseUrlCheckResult | - | 2016-10-02 |
| 88216 | Regression: Use-after-free in CounterNode::insertAfter | $1,000 | 2016-10-02 |
| 87861 | Security: OOB read in svg text run | - | 2016-10-02 |
| 87815 | chrome-devtools:// can be navigated from http | - | 2016-10-02 |
| 87746 | Security: Chrome content script listener | - | 2016-10-02 |
| 87925 | Use after free in range extract contents | $1,000 | 2016-10-02 |
| 87965 | webkitAudioContext multiple issues | - | 2016-10-02 |
| 87862 | Security: Use after free in svg text | - | 2016-10-02 |
| 87701 | Stale pointer in WebCore::PlatformContextSkia::save | - | 2016-10-02 |
| 87548 | use after free in skia blitter | - | 2016-10-02 |
| 87520 | Security: Webpage can gain access to extension content-script variables when content-script triggers events | - | 2016-10-02 |
| 87478 | [LangFuzz] Crash on heap with invalid read | $1,000 | 2016-10-02 |
| 87339 | XSS injection via prototype chain | $500 | 2016-10-02 |
| 87298 | OOB read due to iterating over wrong textbox in TextIterator::emitText (first-letter + RTL) | $500 | 2016-10-02 |
| 87729 | Use after free in third_party/WebKit/LayoutTests/fast/dom/HTMLLinkElement/link-and-subresource-test.html | $1,000 | 2016-10-02 |
| 87728 | Regression(89733): Use after free in fast/forms/text-control-intrinsic-widths.html | $1,000 | 2016-10-02 |
| 87120 | Use after free on 2-Step-Authentication-method-change | $500 | 2016-10-02 |
| 87148 | use after free due to floats not removed | $1,000 | 2016-10-02 |
| 86758 | URL Bar Spoofing using History.back() and History.forward | $500 | 2016-10-02 |
| 86705 | Use after free in Geolocation::fatalErrorOccurred | - | 2016-10-02 |
| 87227 | Use after free due to refcounting issue in MediaQueryMatcher::prepareEvaluator | $1,000 | 2016-10-02 |
| 86900 | Heap memory corruption in web database support (SQLite/ICU) | $1,000 | 2016-10-02 |
| 86502 | Use after free due to floats not cleared from parent's next siblings blocks (on losing ability to intrude floats) | $1,000 | 2016-10-02 |
| 86191 | Security: web-exposed manifest from Chrome extensions diverges from the real manifest in regards to NPAPI | - | 2016-10-02 |
| 86304 | Google Chrome Acess Violation in Frame manipulation | - | 2016-10-02 |
| 86609 | OOB read in fontfallbacklist due to issue in CSSPrimitiveValues clamping | - | 2016-10-02 |
| 86178 | URL bar introduces NUMEROUS vulnerabilities. | - | 2016-10-02 |
| 86648 | Use after free in formassociatedelement not removed from m_formElementsWithFormAttribute | - | 2016-10-02 |
| 86367 | Use after free of frame in Document::finishedParsing | - | 2016-10-02 |
| 85992 | Renderers can have registry handle which would allow a Windows sandbox escape | - | 2016-10-02 |
| 85943 | Use after free in Stylesheet due to issue in CLONE nodes | - | 2016-10-02 |
| 85808 | chrome_1c30000!webkit::ppapi::PPB_Widget_Impl::Invalidate crash | $500 | 2016-10-02 |
| 85559 | Web Inspector: Crash by buffer overrun crash when serializing inspector object tree. | - | 2016-10-02 |
| 86133 | Add GRP to dangerous file list | - | 2016-10-02 |
| 86108 | Security: FileSystem API can be used to learn about installed software on the user's computer | - | 2016-10-02 |
| 85418 | Use-after-free in WebCore::RenderTextControl::isSelectableElement | $1,000 | 2016-10-02 |
| 85309 | Crash when closing a child window that uses a canvas | - | 2016-10-02 |
| 85302 | Crasher in WebCore::StyleBase::stylesheet | - | 2016-10-02 |
| 85256 | OOB read in UniscribleController::advance | - | 2016-10-02 |
| 85211 | Use after free in SVGUseElement::buildShadowTree | $1,000 | 2016-10-02 |
| 85177 | Renderer crash with javascript + setInterval | $500 | 2016-10-02 |
| 85158 | Content script can gain access to the "window" object of the page using custom events | - | 2016-10-02 |
| 85350 | Browser Crash in ~TabContents caused by PrerenderManager::PeriodicCleanup | - | 2016-10-02 |
| 156906 | Heap-use-after-free in WebCore::XMLDocumentParser::doEnd | - | 2016-10-02 |
| 156826 | UNKNOWN in S32A_Blend_BlitRow32_SSE2 | - | 2016-10-02 |
| 156828 | UNKNOWN in WebCore::Font::drawGlyphs | - | 2016-10-02 |
| 156669 | Origin.com somehow manages to open its result page in the previous tab (which was gmail) | - | 2016-10-02 |
| 156619 | Heap-use-after-free in WebCore::ApplyStyleCommand::cleanupUnstyledAppleStyleSpans | - | 2016-10-02 |
| 156431 | Security: Use after free in IDBDatabaseCallbacksImpl::onVersionChange | - | 2016-10-02 |
| 156418 | Heap-use-after-free in SpellCheckHostImpl::SaveDictionaryData | - | 2016-10-02 |
| 156689 | Heap-buffer-overflow in WTF::StringImpl::findIgnoringCase | - | 2016-10-02 |
| 156567 | Security: use-after-free in WebCore::GraphicsContext::paintingDisabled | $1,000 | 2016-10-02 |
| 156282 | Heap-use-after-free in WebCore::StyleResolver::pseudoStyleRulesForElement | - | 2016-10-02 |
| 156383 | Security: chrome_to_device makes use of HTTP for cloudprint | - | 2016-10-02 |
| 156096 | Heap-buffer-overflow in WebCore::RenderBlock::LineBreaker::nextLineBreak | - | 2016-10-02 |
| 156231 | UNKNOWN in _wordcopy_fwd_aligned | $1,000 | 2016-10-02 |
| 156366 | Heap-use-after-free in PluginPlaceholder::ReplacePlugin | - | 2016-10-02 |
| 156152 | Issues with HSTS / public key pins state tracking | - | 2016-10-02 |
| 155977 | Security: remove uses of innerHTML in commented code for Getting Started Guide. | - | 2016-10-02 |
| 155860 | WebCore::SharedBuffer::append(data, 0) can cause unitialized memory to be added to the SharedBuffer | - | 2016-10-02 |
| 155711 | Security: forced oom in browser process due to indefinitely growing buffer in chunked decoder | - | 2016-10-02 |
| 155643 | Heap-use-after-free in content::RenderWidgetHostImpl::OnMsgInputEventAck | - | 2016-10-02 |
| 156015 | Heap-use-after-free in WebCore::FontPlatformData::uniqueID | - | 2016-10-02 |
| 156051 | Heap use-after-free in ExtensionFunctionDispatcher::Dispatch caught by ASan when using "Screen Capture by Google" | - | 2016-10-02 |
| 155877 | Chrome: RenderViewImpl::OnContextMenuClosed(content::CustomContextMenuContext const &) | - | 2016-10-02 |
| 155293 | Heap-use-after-free in WebCore::ContextMenu::appendItem | - | 2016-10-02 |
| 155285 | Heap-use-after-free in WebCore::Node::setNeedsStyleRecalc | - | 2016-10-02 |
| 155117 | Security: GetReadonlyPnaclFD IPC security issues | - | 2016-10-02 |
| 154987 | Pwnium SVG use after free | - | 2016-10-02 |
| 154983 | Security: Pwnium 2 TCMalloc profile bug | $60,000 | 2016-10-02 |
| 155421 | Security: javascript scheme links auto-generated in devtools console | - | 2016-10-02 |
| 154617 | Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
| 155323 | Out of bounds array access in GPU process | - | 2016-10-02 |
| 154926 | Heap-use-after-free in WebIntentPickerGtk::OnDestroyThunk | - | 2016-10-02 |
| 154488 | Heap-use-after-free in WebCore::FrameLoader::stopLoading | - | 2016-10-02 |
| 154465 | Bad cast in webkit_glue::GetSubResourceLinkFromElement | - | 2016-10-02 |
| 154460 | Heap-use-after-free in WebCore::ScrollableArea::scroll | - | 2016-10-02 |
| 154448 | Heap-use-after-free in TransportDIB::DecreaseInFlightCounter | - | 2016-10-02 |
| 154362 | Heap-buffer-overflow in WebCore::HTMLSelectElement::typeAheadFind | - | 2016-10-02 |
| 154590 | Stack-buffer-overflow in SkFontHost::GetAdvancedTypefaceMetrics | - | 2016-10-02 |
| 154485 | Heap-buffer-overflow in std::vector<scoped_refptr<printing::PrintJob>, std::allocator<scoped_refptr<printing::PrintJob> > >: | - | 2016-10-02 |
| 154158 | Security: ensure that a user has willing-fully logged-in to his Google account before triggering the one click Chrome login feature | - | 2016-10-02 |
| 154055 | Heap-use-after-free in WebCore::RenderLayerBacking::paintIntoLayer | $1,000 | 2016-10-02 |
| 153793 | Heap-use-after-free in WebCore::EventHandler::mouseMoved | - | 2016-10-02 |
| 153666 | Security: Bypass for consumable user gesture on pop-up | - | 2016-10-02 |
| 153592 | Heap-use-after-free in WebCore::RenderObject::isDescendantOf | - | 2016-10-02 |
| 154284 | Heap-use-after-free in WebCore::SVGTextRunRenderingContext::glyphDataForCharacter | - | 2016-10-02 |
| 154283 | Heap-buffer-overflow in _HB_GDEF_Check_Property | - | 2016-10-02 |
| 153469 | Security: Nvidia - Kernel Panic - [@ gpu::gles2::GLES2DecoderImpl::ResizeOffscreenFrameBuffer] | - | 2016-10-02 |
| 153239 | Heap-use-after-free in WebCore::GCEpilogueVisitor<void, WebCore::SpecialCaseEpilogueObjectHandler, &WebCore::DOMDataStore:: | - | 2016-10-02 |
| 153228 | Heap-use-after-free in WebCore::SVGImage::drawSVGToImageBuffer | - | 2016-10-02 |
| 153211 | Heap-use-after-free in webrtc::ThreadPosix::Run | - | 2016-10-02 |
| 153566 | Heap-use-after-free in WebCore::FontCache::purgeInactiveFontData | - | 2016-10-02 |
| 153128 | Buffer overrun in Harfbuff | - | 2016-10-02 |
| 153184 | Heap-use-after-free in WebCore::computeNonFastScrollableRegion | - | 2016-10-02 |
| 153048 | Invalid pointer read in std::basic_string | - | 2016-10-02 |
| 152916 | Security: browser process jump to bad address on osx with getUserMedia() and crazyness | - | 2016-10-02 |
| 152707 | Invalid pointer write in GrGpu::clear | $1,000 | 2016-10-02 |
| 152921 | Browser crash, navigator.geolocation.watchPosition issue | - | 2016-10-02 |
| 85102 | Use after free in WebCore::ContainerNode::parserAddChild | $500 | 2016-10-02 |
| 85041 | Memory Corruption in video decoding | - | 2016-10-02 |
| 84946 | Merge http://trac.webkit.org/changeset/87959 and http://trac.webkit.org/changeset/87756 for documentloader use after frees | - | 2016-10-02 |
| 85003 | Parsing issue with -webkit-calc | $1,000 | 2016-10-02 |
| 84950 | Merge http://trac.webkit.org/changeset/87856 | - | 2016-10-02 |
| 84885 | ASSERT obj->parentObject() == this in accessibility tree | - | 2016-10-02 |
| 84919 | Memory corruption in browser process with interstitial that goes back | - | 2016-10-02 |
| 84805 | Flash/GPU memory corruption in critical section. | $500 | 2016-10-02 |
| 84797 | Click Reload this page button after Conway's Game of Life starts causes Aw Snap error | - | 2016-10-02 |
| 84763 | POssible mac use after free in drag & drop code | - | 2016-10-02 |
| 84933 | Browser crash with IndexedDB and very long database names | - | 2016-10-02 |
| 84819 | Bad cast in cloning elements with shadow DOM | - | 2016-10-02 |
| 84597 | use-after-free in WebCore::LevelDBTransaction::commit | - | 2016-10-02 |
| 84584 | Invalid memory access caused by ThumbnailGenerator | - | 2016-10-02 |
| 84452 | Bad cast in HTMLMediaElement::mediaControls | $1,000 | 2016-10-02 |
| 84418 | Shockwave crashed | - | 2016-10-02 |
| 84402 | Extensions permission elevevation using javascript: in homepage_url | - | 2016-10-02 |
| 84355 | use-after-free in svg fontfacelement | $1,000 | 2016-10-02 |
| 84600 | Security: Web page can initiate speech recognition without user knowing about it | - | 2016-10-02 |
| 84234 | [LangFuzz] Crash @ MarkCompactCollector::SweepSpaces() or SeqTwoByteString::SeqTwoByteStringReadBlockIntoBuffer() (64 bit) | $1,000 | 2016-10-02 |
| 84160 | Use after free in accessibility notifications. | - | 2016-10-02 |
| 84016 | Use after free in BrowserAccessibility::DetachTree | - | 2016-10-02 |
| 84002 | OOB read in ComplexTextController constructor (ComplexTextControllerLinux.cpp) + OOB read in WidthIterator | - | 2016-10-02 |
| 83917 | OOB Write in Skia Shader Blitter | - | 2016-10-02 |
| 83903 | Vai | - | 2016-10-02 |
| 83848 | Use after free in LayerChromium::~LayerChromium | - | 2016-10-02 |
| 83841 | User information leakage esp local paths, username in webgl getProgramInfoLog | - | 2016-10-02 |
| 84333 | use after free in WebCore::ContainerNode::firstChild / WebCore::XMLDocumentParser::insertErrorMessageBlock | - | 2016-10-02 |
| 83672 | Stale layout root set as input element when child of a keygen with autofocus | - | 2016-10-02 |
| 83598 | OOB read in WebCore::parseColorIntOrPercentage | - | 2016-10-02 |
| 83275 | UXSS with window.execScript | $3,133 | 2016-10-02 |
| 83273 | Browser prompt when installing unpacked npapi extensions | - | 2016-10-02 |
| 83270 | oob read in WebCore::ImageBufferData::getData | - | 2016-10-02 |
| 83743 | Universal XSS using contentWindow.eval | $1,000 | 2016-10-02 |
| 83235 | Bad cast in RenderBlock::createLineBoxes due to double attach in htmlformelement | - | 2016-10-02 |
| 83012 | Use after free in XMLDocumentParser | - | 2016-10-02 |
| 83010 | An extension can access and modify all chrome:// pages, options, etc. | $1,000 | 2016-10-02 |
| 82903 | OOB write in BlobURLRequestJob::HeadersCompleted | - | 2016-10-02 |
| 82873 | Memory corruption in GPU command buffer | - | 2016-10-02 |
| 83031 | Chrome spoof on 302 redirect | - | 2016-10-02 |
| 82841 | Browser crash @ closing chrome://settings/syncSetup | - | 2016-10-02 |
| 82817 | buffer overflow marshalling data from sandbox | - | 2016-10-02 |
| 82653 | Use after free due to incorrectly setting document.body to non body elements, elements from other docs. | - | 2016-10-02 |
| 82633 | Bad cast in CSSParser::createFontFaceRule | - | 2016-10-02 |
| 82597 | document.execCommand('copy') return always false | - | 2016-10-02 |
| 82552 | REGRESSION (83075): Use after free in line box culling optimization | - | 2016-10-02 |
| 82546 | Stale pointer in WebCore::RenderBlock::marginBeforeForChild | $1,000 | 2016-10-02 |
| 82516 | write-after-free in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h:58 | - | 2016-10-02 |
| 82438 | OOB read in media::FFmpegVideoDecodeEngine::Initialize | - | 2016-10-02 |
| 82416 | IndexedDB crash on index.getKey | - | 2016-10-02 |
| 82309 | CRASH @ DownloadItem::UpdateObservers() | - | 2016-10-02 |
| 82184 | Renderer crash @ GrTHashTable<GrGpuGLShaders::ProgramCache::Entry,GrBinHashKey<GrGpuGLShaders::ProgramCache::Entry,32>,8>::remove(GrBinHashKey<GrGpuGLShaders::ProgramCache::Entry,32> const &,GrGpuGLShaders::ProgramCache::Entry const *) | - | 2016-10-02 |
| 82161 | Google Chrome (Pwned) | - | 2016-10-02 |
| 82154 | out-of-bound access in third_party/WebKit/Source/WebKit/chromium/src/WebFrameImpl.cpp | - | 2016-10-02 |
| 82152 | Need to merge WebKit 64-bit issue http://trac.webkit.org/changeset/86106 | - | 2016-10-02 |
| 82096 | Merge http://trac.webkit.org/changeset/85693 | - | 2016-10-02 |
| 82444 | Local file disclosure when pasting stuff from Excel, etc. | - | 2016-10-02 |
| 82018 | TEST TEST IGNORE | - | 2016-10-02 |
| 81949 | use-after-free in imageloader with fallbackcontent | $1,000 | 2016-10-02 |
| 82083 | Google Chrome Pwned by VUPEN aka Sandbox/ASLR/DEP Bypass | - | 2016-10-02 |
| 161077 | Invalid pointer write in GrRenderTarget::onRelease | $1,000 | 2016-10-02 |
| 161089 | Indexeddb createIndex() crashes the page | - | 2016-10-02 |
| 161015 | Heap-use-after-free in WebCore::HTMLConstructionSite::mergeAttributesFromTokenIntoElement | - | 2016-10-02 |
| 161239 | Heap-use-after-free in WebCore::IDBTransactionBackendImpl::taskTimerFired | - | 2016-10-02 |
| 160926 | Security:Check for integer wrap in PPB_ImageData_Impl::Init() is insufficient | - | 2016-10-02 |
| 160480 | Security: Integer overflow in opus_packet_parse_impl | - | 2016-10-02 |
| 160450 | Heap-buffer-overflow in WebCore::InlineFlowBox::placeBoxRangeInInlineDirection | - | 2016-10-02 |
| 160380 | Heap-use-after-free in WebKit::ChromePrintContext::spoolPage | - | 2016-10-02 |
| 160760 | Security: NaCl sandbox escape; missing register check across a superinstruction | - | 2016-10-02 |
| 160803 | Security: ugly crash with history.replaceState() while the window displays HTTPS interstitial | - | 2016-10-02 |
| 160456 | Security: Restrict chromoting viewer plugin to chromoting extension | - | 2016-10-02 |
| 160010 | [LangFuzz] Crash at v8::internal::BasicJsonStringifier::SerializeString | $1,000 | 2016-10-02 |
| 159829 | Heap-buffer-overflow in WebCore::HTMLInputElement::isImageButton | - | 2016-10-02 |
| 159828 | Heap-use-after-free in WebCore::RenderLayer::hitTest | - | 2016-10-02 |
| 159553 | Security: Integer overflow in remoting viewer AudioDecoderSpeex::Decode | - | 2016-10-02 |
| 159429 | Security: Use after free on ~AssociatedURLLoader with pdf plugin | $1,000 | 2016-10-02 |
| 159338 | Heap-use-after-free in WebCore::SVGDocumentExtensions::removeAllElementReferencesForTarget | $1,000 | 2016-10-02 |
| 160068 | Merge http://trac.webkit.org/changeset/133840 | - | 2016-10-02 |
| 160038 | Security: Unquoted Path vulnerability in GoogleCrashHandler | - | 2016-10-02 |
| 159165 | Heap-use-after-free in webkit::ppapi::PluginInstance::PrintBegin | - | 2016-10-02 |
| 159229 | Security: Integer overflow in remoting viewer AudioDecoderOpus::Decode | - | 2016-10-02 |
| 158992 | Heap-use-after-free in WebCore::RenderTextTrackCue::layout | - | 2016-10-02 |
| 158898 | Heap-use-after-free in WebCore::RenderBlock::removeChild | - | 2016-10-02 |
| 158897 | Heap-buffer-overflow in WebCore::RenderBlock::clone | - | 2016-10-02 |
| 159219 | Heap-use-after-free in WebCore::EventHandler::handleMousePressEvent | - | 2016-10-02 |
| 159098 | Heap-buffer-overflow in WebCore::TextTrackCueList::add | - | 2016-10-02 |
| 158693 | Heap-use-after-free in WebCore::RenderLayerModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 158695 | Heap-use-after-free in WebCore::WidgetHierarchyUpdatesSuspensionScope::moveWidgets | - | 2016-10-02 |
| 158533 | Heap-use-after-free in WebCore::RenderLayer::paintLayerContents [MathML] | - | 2016-10-02 |
| 158457 | Heap-use-after-free in non-virtual thunk to content::RenderViewImpl::createPopupMenu | - | 2016-10-02 |
| 158249 | Security: Heap-buffer-underflow in xmlParseAttValueComplex | - | 2016-10-02 |
| 158204 | Heap-use-after-free in WebCore::Frame::dispatchVisibilityStateChangeEvent | $1,500 | 2016-10-02 |
| 158199 | Heap-use-after-free in WebCore::StyleCachedImageSet::cssValue | - | 2016-10-02 |
| 158707 | Heap-use-after-free in WebCore::RenderObject::isBody | - | 2016-10-02 |
| 158547 | Heap-use-after-free in WebCore::HTMLInputElement::setValue for type=range, type=date, and type=time with datalist | - | 2016-10-02 |
| 158060 | Heap-use-after-free in WebCore::CachedResource::checkNotify | - | 2016-10-02 |
| 157951 | Heap-use-after-free in non-virtual thunk to WebKit::DateTimeChooserImpl::setValueAndClosePopup | - | 2016-10-02 |
| 157875 | Heap-use-after-free in WebCore::OpenTypeVerticalData::substituteWithVerticalGlyphs | - | 2016-10-02 |
| 157845 | Heap-use-after-free in skia::BGRAConvolve2D | $500 | 2016-10-02 |
| 157779 | Heap-use-after-free in WebKit::WebMediaStreamDescriptor::label | - | 2016-10-02 |
| 157778 | Heap-use-after-free in WebCore::CSSStyleRule::style | - | 2016-10-02 |
| 157585 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::~BaseMultipleFieldsDateAndTimeInputType | - | 2016-10-02 |
| 158065 | Stack-buffer-overflow in WebCore::SVGMaskElement::~SVGMaskElement | - | 2016-10-02 |
| 157463 | Heap-use-after-free in content::LocalVideoCapture::Stop | - | 2016-10-02 |
| 157516 | Security: XSS auditor can sometimes be used to maliciously alter form action property. | - | 2016-10-02 |
| 157363 | Heap-buffer-overflow in void std::__final_insertion_sort<WebCore::SMILTimeWithOrigin*> | - | 2016-10-02 |
| 157289 | Invalid cast in WebCore::toInsertionPoint / WebCore::ContentDistributor::distribute | - | 2016-10-02 |
| 157462 | Heap-use-after-free in webrtc::MediaStreamSignaling::UpdateRemoteStreams | - | 2016-10-02 |
| 157079 | Security: Integer overflow in libwebp "ParseOptionalChunks" allows memory disclosure | $3,500 | 2016-10-02 |
| 157071 | Heap-use-after-free in non-virtual thunk to WebKit::DateTimeChooserImpl::setValueAndClosePopup | - | 2016-10-02 |
| 157019 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 157124 | UNKNOWN in v8::internal::ObjectHashTable::Put | - | 2016-10-02 |
| 157053 | Heap-use-after-free in WebCore::Element::attributeChanged | - | 2016-10-02 |
| 156977 | Heap-use-after-free in WebCore::RenderText::removeAndDestroyTextBoxes | - | 2016-10-02 |
| 156980 | Security: workers can initialize the sandbox multithreaded | - | 2016-10-02 |
| 157009 | Heap-use-after-free in WebCore::SubresourceLoader::willSendRequest | - | 2016-10-02 |
| 81947 | Use after free in WebCore::requiresLineBox | - | 2016-10-02 |
| 81753 | Valgrind reports issues in icu_46::RegexMatcher | - | 2016-10-02 |
| 81916 | Stale observer in BrowsingDataRemover's observer_list_ | $500 | 2016-10-02 |
| 81351 | CSSSelector double frees | - | 2016-10-02 |
| 81348 | Use after free when removing elements with reflections | - | 2016-10-02 |
| 81307 | Security: dropping file:/// URLs into gmail grants access to files | - | 2016-10-02 |
| 81803 | out-of-bounds use in SkBitmapOperations::CreateMaskedBitmap | - | 2016-10-02 |
| 81681 | Memory corruption in GraphicsContext::fillPath | - | 2016-10-02 |
| 80680 | Security: .keystone_install_lock is insecurely handled in install.py | - | 2016-10-02 |
| 80608 | Multiple integer overflows in SVG filter effects | - | 2016-10-02 |
| 80401 | Url bar spoof using onbeforeunload when user cancels navigation | - | 2016-10-02 |
| 80358 | WebCore::InspectorBackendDispatcher::Runtime_evaluate user after free | - | 2016-10-02 |
| 81234 | Flash content vulnerability | - | 2016-10-02 |
| 80255 | use after free in WebCore::RenderSVGInlineText::characterStartsNewTextChunk | - | 2016-10-02 |
| 80222 | Herror of chrome | - | 2016-10-02 |
| 80287 | Regression(81992): Stale node set as layout root | - | 2016-10-02 |
| 80116 | Stale pointer in WebCore::Document::recalcStyleSelector | - | 2016-10-02 |
| 79746 | Floats not cleared due to overflow (remaining usecase) | $1,000 | 2016-10-02 |
| 79726 | BrowserAccessibility browser process memory corruption | - | 2016-10-02 |
| 79668 | invalid read w/new skia update | - | 2016-10-02 |
| 79661 | Sandbox is broken (low integrity level) | - | 2016-10-02 |
| 79595 | Bad cast due to childrenInline assumption in RenderSVGText | - | 2016-10-02 |
| 79566 | Bypass extensions permission | $500 | 2016-10-02 |
| 79862 | Bypass extensions permission app launch web_url should not allow javascript: chrome: | - | 2016-10-02 |
| 79452 | H | - | 2016-10-02 |
| 79426 | HTTP Basic Auth Realm Spoof | - | 2016-10-02 |
| 79371 | Use after free in ImplicitAnimation::~ImplicitAnimation | - | 2016-10-02 |
| 79362 | Reproducible PDF crash (siryo3.pdf) | - | 2016-10-02 |
| 79266 | Bypass unsafe file types dialog | - | 2016-10-02 |
| 79075 | Stale node set as layout root, due to one caption not laid out in table with two captions | - | 2016-10-02 |
| 79055 | Freed m_viewportRenderer in FrameView::updateOverflowStatus | - | 2016-10-02 |
| 79025 | Use after free when inline runin precedes details tag | - | 2016-10-02 |
| 78948 | Integer underflow in HTMLFormElement::m_associatedElementsAfterIndex | - | 2016-10-02 |
| 78861 | Memory corruption in RenderViewHost related to observers code | - | 2016-10-02 |
| 78842 | proslor.co.be | - | 2016-10-02 |
| 78841 | invalid access with bad html | $1,000 | 2016-10-02 |
| 78798 | Security: XSS in dev tools HTML inspector | - | 2016-10-02 |
| 78639 | Memory corruption leading to OOB read symptom in PDF initialization | $1,000 | 2016-10-02 |
| 78576 | compareDocumentPosition memory corruption | - | 2016-10-02 |
| 78575 | Bad cast in reverseInlineBoxRangeAndValueListsIfNeeded | - | 2016-10-02 |
| 78572 | CounterNode memory corruption | - | 2016-10-02 |
| 78558 | chrome bug | - | 2016-10-02 |
| 78524 | ANGLE buffer overflow | $1,000 | 2016-10-02 |
| 78516 | Looks like a stale frame in UserScriptSlave::InjectScripts | - | 2016-10-02 |
| 78427 | url spoof through bookmark bar click | - | 2016-10-02 |
| 78401 | Stale node being set as layout root | - | 2016-10-02 |
| 78327 | Integer overflow in FilterEffect::copyImageBytes | - | 2016-10-02 |
| 78296 | False warning of Google Chrome / Fake Antimalware Tool | - | 2016-10-02 |
| 78270 | [LangFuzz] V8: Crash in HeapObject::map_word on GC | $1,000 | 2016-10-02 |
| 78559 | chrome bug | - | 2016-10-02 |
| 78106 | ZDI-CAN-1108: WebKit ContentEditable Inline Style Remote Code Execution | - | 2016-10-02 |
| 78071 | css parsing issue in calc | $1,000 | 2016-10-02 |
| 78038 | ThreadSanitizer reports a potential use after free in net::X509Certificate::Verify | - | 2016-10-02 |
| 78031 | Url bar spoof | $1,000 | 2016-10-02 |
| 78145 | Invalid write in SVGTextLayoutEngine | - | 2016-10-02 |
| 78053 | Stale m_fontList in svgFontAndFontFaceElementForFontData | - | 2016-10-02 |
| 165747 | IPC: renderer out-of-bounds crash creating 3D context from malformed PPAPI message | - | 2016-10-02 |
| 165836 | Information leak when sending messages cross process that use WriteData() on structures/objects which contain padding bytes. | - | 2016-10-02 |
| 165549 | Security: Sandbox isolation not working | - | 2016-10-02 |
| 165602 | Heap-use-after-free in WebCore::CSSStyleRule::style | - | 2016-10-02 |
| 165804 | Security: SnapshotProvider exposed to other applications on the device | - | 2016-10-02 |
| 165601 | Heap-use-after-free in matroska_parse_block | - | 2016-10-02 |
| 165456 | Heap-use-after-free in WebCore::Element::hasPendingResources | - | 2016-10-02 |
| 165430 | Heap-buffer-overflow in media::AudioRendererAlgorithm::OutputFasterPlayback | - | 2016-10-02 |
| 165102 | Security: devtool xss | - | 2016-10-02 |
| 165091 | Bypassing Chrome's XSS filter, XSSAuditor | - | 2016-10-02 |
| 165537 | PDF: off-by-one read when scanning for startxref | - | 2016-10-02 |
| 165538 | PDF: integer overflows in JS array handling | - | 2016-10-02 |
| 165432 | Use after free in SVG path | $500 | 2016-10-02 |
| 164958 | IPC: PPAPI messages have problems with use of signed integers for lengths | - | 2016-10-02 |
| 165015 | Heap-use-after-free in WebCore::Element::normalizeAttributes | $1,000 | 2016-10-02 |
| 164701 | PDF: regressions due to merge losing previous security fixes | - | 2016-10-02 |
| 164697 | PDF: regressions in JBIG2 codec | - | 2016-10-02 |
| 164682 | Input validation error in BrowserPluginEmbedderHelper::OnHandleInputEvent() leads to bad cast | - | 2016-10-02 |
| 164643 | Security: ASan reports a use-after-free while using SecureShell | - | 2016-10-02 |
| 165009 | Heap-use-after-free in WebCore::SVGSMILElement::disconnectConditions | - | 2016-10-02 |
| 164946 | IPC: GPU messages have integer truncation (bad use of size_t) and integer sign extension (bad use of signed type) issues | - | 2016-10-02 |
| 164582 | Heap-buffer-overflow in SkRectClipBlitter::blitAntiH | - | 2016-10-02 |
| 164581 | Heap-use-after-free in WebCore::TextTrackCue::isActive | - | 2016-10-02 |
| 164565 | Security: V8 bug may give out-of-bounds access to the stack | - | 2016-10-02 |
| 164490 | IPC: integer overflow in Windows' SharedMemory::Create | - | 2016-10-02 |
| 164454 | switch off mathml for m24 | - | 2016-10-02 |
| 164263 | Heap-use-after-free in WebCore::FrameSelection::directionOfSelection | - | 2016-10-02 |
| 164584 | Translate should load resources over HTTPS even if the original page is loaded via HTTP. | - | 2016-10-02 |
| 163593 | Heap-use-after-free in WebCore::RenderBlock::finishDelayUpdateScrollInfo [MathML] | - | 2016-10-02 |
| 163588 | IPC::Channel::ChannelImpl::ProcessOutgoingMessages - crash | - | 2016-10-02 |
| 163291 | Heap-buffer-overflow in WebCore::RenderGrid::layoutGridItems | - | 2016-10-02 |
| 163238 | Security: XSS in bug tracker? <script>alert(0)</script> again? | - | 2016-10-02 |
| 163218 | Heap-use-after-free in webkit_glue::WebURLLoaderImpl::Context::OnReceivedResponse | - | 2016-10-02 |
| 163994 | Heap-use-after-free in WebCore::CachedResource::checkNotify | - | 2016-10-02 |
| 163203 | IndexedDB: Assert hit in IDBObjectStoreBackendImpl::setIndexesReady | - | 2016-10-02 |
| 162896 | Out of bounds read in WTF::String::String / WebCore::WebVTTParser::constructTreeFromToken | - | 2016-10-02 |
| 163208 | Security: Workers don't initialize a sandbox on Mac | - | 2016-10-02 |
| 162835 | Heap-use-after-free in WebCore::MediaPlayer::sourceSetTimestampOffset [exploitable] | $7,331 | 2016-10-02 |
| 162778 | PDF: use-after-frees in field name tree again | - | 2016-10-02 |
| 162776 | PDF: out-of-bounds reads with crazy bits per component / num components values | - | 2016-10-02 |
| 163110 | Heap-use-after-free in WebCore::ApplyStyleCommand::pushDownInlineStyleAroundNode | - | 2016-10-02 |
| 162620 | Heap-use-after-free in WebCore::RenderSVGResourcePattern::applyResource | - | 2016-10-02 |
| 162551 | Access violation write in _VEC_memcpy | $1,000 | 2016-10-02 |
| 162489 | Security: Small info leak in the SUID sandbox helper? | - | 2016-10-02 |
| 162156 | PDF: more out-of-bounds reads with mismatched colorspaces | - | 2016-10-02 |
| 162622 | Heap-use-after-free in WebCore::RenderBlock::willBeDestroyed | - | 2016-10-02 |
| 162494 | Heap-use-after-free in WebCore::PopStateEvent::~PopStateEvent | $1,000 | 2016-10-02 |
| 162114 | Security: Renderer sandbox bypass by crafting LevelDB database in "profile/File System/" | - | 2016-10-02 |
| 162115 | Heap-buffer-overflow in SkA8_Blitter::blitH | - | 2016-10-02 |
| 162032 | Heap-use-after-free in udat_close_46 | - | 2016-10-02 |
| 161836 | Security: Possible directory traversal vulnerability in ExtensionResource::GetFilePath(). | - | 2016-10-02 |
| 161690 | Heap-use-after-free in WebCore::RenderSVGResourceContainer::markClientForInvalidation | - | 2016-10-02 |
| 161662 | Heap-use-after-free in media::BlockingUrlProtocol::SignalReadCompleted | - | 2016-10-02 |
| 162153 | PDF: bad cast if root page is not a dictionary object | - | 2016-10-02 |
| 162066 | LOGFONT IPC deserializer doesn't require NULL terminated lfFaceName | - | 2016-10-02 |
| 161564 | Security: Renderer sandbox bypass on ChildProcessSecurityPolicyImpl::SecurityState::HasPermissionsForFile() | - | 2016-10-02 |
| 161484 | UNKNOWN in WebCore::RenderObject::propagateStyleToAnonymousChildren | - | 2016-10-02 |
| 161478 | Heap-buffer-overflow in WebCore::Biquad::process | - | 2016-10-02 |
| 161458 | Heap-buffer-overflow in apply_kernel_interp | - | 2016-10-02 |
| 161420 | Heap-buffer-overflow in WTF::StringImpl::create | - | 2016-10-02 |
| 161639 | Security: ffmpeg oob write4 (222) | $2,000 | 2016-10-02 |
| 161340 | Security: GPU sandbox is always disabled because of watchdog thread on Linux | - | 2016-10-02 |
| 161240 | Heap-use-after-free in WebCore::AccessibilityRenderObject::remoteSVGRootElement | - | 2016-10-02 |
| 77633 | write-after-free in v8::internal::RegExpMacroAssemblerX64::~RegExpMacroAssemblerX64 | - | 2016-10-02 |
| 77917 | Looks like a bad cast in RenderInputSpeech::paintInputFieldSpeechButton | - | 2016-10-02 |
| 77786 | URL Bar Spoofing using redirection and location.reload(); | $500 | 2016-10-02 |
| 77765 | 12 bad cast in editing code relating to htmlelement conversions, isprimitivevalue problems. | - | 2016-10-02 |
| 77703 | Use-after-free in WebCore::isDeletableElement | - | 2016-10-02 |
| 77700 | Captured an attack used against Chrome on many google image links, uses chromes own error template against itself | - | 2016-10-02 |
| 77690 | Use after free in WebCore::ContainerNode::insertedIntoDocument / WebCore::SVGElement::insertedIntoDocument | - | 2016-10-02 |
| 77940 | ZDI-CAN-1021: Apple Safari Webkit SVG Marker Remote Code Execution Vulnerability | - | 2016-10-02 |
| 77812 | Security: Chrome Security Pop-up | - | 2016-10-02 |
| 77669 | Bad cast in WebCore::BreakBlockquoteCommand::doApply | - | 2016-10-02 |
| 77507 | URL Bar Spoof | $1,000 | 2016-10-02 |
| 77493 | OOB read with Flash | $1,000 | 2016-10-02 |
| 77349 | When object destroyed, its select file dialog is not informed to cleared its listener which can call back that destroyed object | - | 2016-10-02 |
| 77346 | Use After Free in Websockets - possible remote code execution within sandbox | $1,000 | 2016-10-02 |
| 77181 | OOB function pointer array call FEComponentTransfer::apply | - | 2016-10-02 |
| 77130 | stale entries in gPercentHeightDescendantsMap | $1,000 | 2016-10-02 |
| 77053 | Bad cast in HTMLTreeBuilder with closed </form> tags | - | 2016-10-02 |
| 77038 | repair | - | 2016-10-02 |
| 77026 | Bypass extension manifest permission | $1,337 | 2016-10-02 |
| 76966 | RIP goes to zero with select tag, and form validation message with position:relative | $1,000 | 2016-10-02 |
| 76955 | Renderer crash when visiting http://runescape.wikia.com/wiki/Special:Search | - | 2016-10-02 |
| 76784 | Bad cast to RenderBlock in accessibility assuming that anonymous blocks are renderblocks. | - | 2016-10-02 |
| 76771 | use after free in WebCore::ScriptWrappable::wrapper | - | 2016-10-02 |
| 76666 | URL bar spoof | $1,000 | 2016-10-02 |
| 76646 | OOB read in FEDisplacementMap::apply | - | 2016-10-02 |
| 76589 | Crash@ anonymous namespace'::PureCall() when navigate to previous page while speech input API fetching result text | - | 2016-10-02 |
| 76542 | Linux setuid sandbox allows local privilege escalation | $500 | 2016-10-02 |
| 76474 | crash in WebKit::WebPluginContainerImpl::handleEvent() | - | 2016-10-02 |
| 76202 | DownloadThrottlingResourceHandler::OnResponseCompleted NOTREACHED() | - | 2016-10-02 |
| 76198 | Bad cast in HTMLTreeBuilder::processStartTag | - | 2016-10-02 |
| 76528 | use after free in AnimationBase::next / AnimationControllerPrivate::styleAvailable | - | 2016-10-02 |
| 76194 | bad cast in WebCore::toRenderBoxModelObject / WebCore::RenderMathMLRoot::layout | - | 2016-10-02 |
| 76059 | WebCore::LayerTilerChromium::invalidateRect() - crash | $1,000 | 2016-10-02 |
| 76031 | Crash when visiting http://kikafriends.forumcommunity.net/ | - | 2016-10-02 |
| 76029 | Crash in webcore::rendertable::cellafter when visiting http://broadband.biglobe.ne.jp/ | - | 2016-10-02 |
| 76027 | securiti | - | 2016-10-02 |
| 76018 | Crash in network stack when running http/tests/loading/redirect-methods.html | - | 2016-10-02 |
| 76195 | potential bad cast in WebCore::toRenderCombineText/WebCore::RenderBlock::computeInlinePreferredLogicalWidths | - | 2016-10-02 |
| 76034 | Security:Instant hard-crash with JS code | - | 2016-10-02 |
| 75821 | Should we reconsider the no-client-UI decision for the web store? | - | 2016-10-02 |
| 75712 | Integer overflow in style elements | $1,337 | 2016-10-02 |
| 76001 | Stale pointer in WebCore::LayerRendererChromium::drawLayer | $1,000 | 2016-10-02 |
| 75835 | use of freed pointer in WebCore::RenderCounter::originalText() | - | 2016-10-02 |
| 75696 | Security: pushState() should be available only for origin-bearing schemes | - | 2016-10-02 |
| 75496 | chrome.dll!BrowserAccessibility..InternalReleaseReference ExecAV@NULL (cc7203fb809bd98728cf74b908e66edf) | - | 2016-10-02 |
| 75629 | Use after free in gpu::gles2::ShaderTranslator | - | 2016-10-02 |
| 75643 | CSS visited history disclosure | - | 2016-10-02 |
| 75436 | Detach Geolocation from Frame when Page destroyed. | - | 2016-10-02 |
| 75560 | Security: address bar updates not synchronized with document transitions | - | 2016-10-02 |
| 75186 | (WebCore::RenderObjectChildList::destroyLeftoverChildren) Use-after-free with nesting ruby tag and css propierties | $1,000 | 2016-10-02 |
| 75210 | Harfbuzz segfault in GPOS_Do_Glyph_Lookup | - | 2016-10-02 |
| 75021 | Use-after-free in InfoBar since ~r76800 | - | 2016-10-02 |
| 75311 | Bad cast in HTMLTreeBuilder::processStartTag | - | 2016-10-02 |
| 75347 | Bad cast to RenderBlock with floating select element with required attribute | $500 | 2016-10-02 |
| 75155 | Integer overflow in WebCore::GraphicsContext::fillRect (Mac) | - | 2016-10-02 |
| 75070 | Security: do not ignore type= on <object> | - | 2016-10-02 |
| 75374 | REGRESSION (r80320): Bad cast assertion failure when processing mis-nested foreign content. | - | 2016-10-02 |
| 74678 | v8 fuzzing - 1175 - use after free | $1,000 | 2016-10-02 |
| 74763 | Security: Domui process can be ptraced from a compromised renderer leading to sandbox escape | - | 2016-10-02 |
| 74887 | memcpy from TexSubImage2D causes memory corruption | - | 2016-10-02 |
| 74891 | chrome://appcache-internals/ xss | - | 2016-10-02 |
| 74720 | Read uninitialized value from JavaScript. | - | 2016-10-02 |
| 74677 | v8 fuzzing - 1160 - bad cast of object to string in array join | - | 2016-10-02 |
| 169685 | Missing validation of webkit_base::DataElement across IPC | - | 2016-10-02 |
| 169672 | Heap-buffer-overflow in WTF::AtomicString::add | - | 2016-10-02 |
| 169632 | Security: extensions can silently gain file: host permissions via permissions API | - | 2016-10-02 |
| 74675 | v8 fuzzing - 1146 - invalid memory access | $1,000 | 2016-10-02 |
| 74673 | v8 fuzzing - 1166 - exploitable write | $1,000 | 2016-10-02 |
| 74672 | v8 fuzzing - 1138 - use after free | $1,000 | 2016-10-02 |
| 74671 | v8 fuzzing - 1136 - corrupt JIT code | $1,000 | 2016-10-02 |
| 169247 | Attempting free in content::PeerConnectionTracker::UnregisterPeerConnection | - | 2016-10-02 |
| 169156 | Security: Use after free in FlingAnimatorImplAndroid - writing value to this after this is deleted | - | 2016-10-02 |
| 169054 | Security: memory corruption with webgl on linux intel driver | $3,133 | 2016-10-02 |
| 169295 | IPC: bad pointer used in browser if renderer sends mismatched vector lengths | - | 2016-10-02 |
| 169398 | Heap-use-after-free in WebCore::RenderBlock::willBeDestroyed | - | 2016-10-02 |
| 169401 | Security: JavaScript injection into arbitrary web pages via Intent with JavaScript URI | $500 | 2016-10-02 |
| 168968 | Heap-use-after-free in DownloadRequestInfoBarDelegate::~DownloadRequestInfoBarDelegate | - | 2016-10-02 |
| 169006 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
| 168768 | Heap-use-after-free in WebKit::WebMediaPlayerClientImpl::AudioSourceProviderImpl::setClient | $1,000 | 2016-10-02 |
| 168710 | IPC: avoid operator-new based integer overflow in Flash menu deserialization | - | 2016-10-02 |
| 168982 | Heap-use-after-free in WebCore::SVGAnimateMotionElement::updateAnimationPath | - | 2016-10-02 |
| 168969 | Heap-use-after-free in WebCore::Element::hasPendingResources | - | 2016-10-02 |
| 168780 | Heap-use-after-free in WebCore::RenderObject::willBeRemovedFromTree | - | 2016-10-02 |
| 168473 | Heap-buffer-overflow in vorbis_floor0_decode | - | 2016-10-02 |
| 168570 | Crashing in webkit_media::WebMediaPlayerMS::putCurrentFrame(WebKit::WebVideoFrame *) | - | 2016-10-02 |
| 168489 | Heap-use-after-free in WebCore::AccessibilityNodeObject::document | - | 2016-10-02 |
| 168442 | Security: Non-privileged extensions can monitor browsing activity via chrome.tabs.onUpdated events | - | 2016-10-02 |
| 167840 | Linux sandbox bypass in file_util_posix.cc CopyDirectory() | - | 2016-10-02 |
| 167788 | Security: heap-buffer-overflow on GetImageRepToPaint. | - | 2016-10-02 |
| 167780 | Heap-use-after-free in bool WebCore::SelectorChecker::checkOneSelector<WebCore::DOMSiblingTraversalStrategy> | - | 2016-10-02 |
| 167868 | Heap-use-after-free in WebCore::Document::updateHoverActiveState | - | 2016-10-02 |
| 168050 | Attacker controlled size mismatch in WidgetDidReceivePaintAtSizeAck() | - | 2016-10-02 |
| 167827 | Heap-use-after-free in WebCore::Element::cloneElementWithoutChildren | - | 2016-10-02 |
| 167924 | Heap-use-after-free in WebCore::RenderLayerModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 167498 | Heap-use-after-free in WebCore::CSSStyleRule::style | - | 2016-10-02 |
| 167443 | Heap-buffer-overflow in WebCore::FontCache::releaseFontData | - | 2016-10-02 |
| 167412 | IPC: GPU message OnMsgAssignPictureBuffers incorrectly assumed same-sized vectors | - | 2016-10-02 |
| 167728 | Heap-use-after-free in WebCore::SVGTransformListV8Internal::numberOfItemsAttrGetter | - | 2016-10-02 |
| 167607 | Security: Failure to enforce key usage | - | 2016-10-02 |
| 167572 | Heap-use-after-free in WebCore::HTMLConstructionSite::mergeAttributesFromTokenIntoElement | - | 2016-10-02 |
| 167147 | Heap-use-after-free in WebCore::Document::implicitClose | - | 2016-10-02 |
| 167122 | HyphenatorHostMsg_OpenDictionary IPC allows arbitrary file reads from a compromised renderer | - | 2016-10-02 |
| 167110 | Heap-buffer-overflow in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
| 167069 | Heap-buffer-overflow in matroska_parse_block | $500 | 2016-10-02 |
| 166916 | Security: mixed content XHR doesn't trigger mixed content warnings | - | 2016-10-02 |
| 166867 | Security: ReferencesParent bypass with a 0x00 byte | - | 2016-10-02 |
| 166795 | Harden audio stream creation in the browser | - | 2016-10-02 |
| 167180 | Security: NaCl ARM validator sandbox escape, Chrome M25 | - | 2016-10-02 |
| 167311 | Heap-use-after-free in WebCore::GenericEventQueue::enqueueEvent | - | 2016-10-02 |
| 167218 | Arbitrary server response with Content-Encoding including sdch can cause crashes if sdch is not configured | - | 2016-10-02 |
| 166621 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
| 166565 | Heap-buffer-overflow in media::AudioBus::FromInterleavedPartial | - | 2016-10-02 |
| 166554 | [LangFuzz] Crash at v8::internal::Deoptimizer::DoComputeOutputFrames with invalid read | $1,000 | 2016-10-02 |
| 166553 | [LangFuzz] Crash at v8::internal::HeapObject::SizeFromMap with invalid read | $1,000 | 2016-10-02 |
| 166523 | [Mac] apprtc crashes when output sampling rate set to 96000 Hz | - | 2016-10-02 |
| 166513 | Heap-use-after-free in WebCore::StyledElement::ensureMutableInlineStyle | - | 2016-10-02 |
| 166503 | audio getUserMedia call crashes tab when input sampled at 88200 Hz | - | 2016-10-02 |
| 166708 | BrowserPluginGuest blindly trusts the size of shared memory regions leading to overflow | - | 2016-10-02 |
| 166627 | Heap-use-after-free in WebCore::Prerender::didStartPrerender | - | 2016-10-02 |
| 166324 | Heap-use-after-free in WebCore::RenderBlock::insertIntoTrackedRendererMaps | - | 2016-10-02 |
| 166336 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 166271 | PDF: use-after-free in colorspace cache | - | 2016-10-02 |
| 166257 | Security: ChromeBrowserSyncAdapterService is exported, but does not need to be? | - | 2016-10-02 |
| 165928 | Heap-use-after-free in WebCore::SVGSMILElement::isSMILElement | - | 2016-10-02 |
| 166493 | IPC: missing integer checks on Pepper UDP socket handling | - | 2016-10-02 |
| 166306 | WebCore::SMILTimeContainer::updateAnimations - crash | - | 2016-10-02 |
| 165926 | Heap-use-after-free in WTF::Vector<WTF::RefPtr<WebCore::Node>, 0ul>::shrinkCapacity | - | 2016-10-02 |
| 165864 | Heap-use-after-free in WebCore::ChildNodeInsertionNotifier::notifyDescendantInsertedIntoDocument | $1,000 | 2016-10-02 |
| 74665 | v8 fuzzing - 1109 (out of bounds write) | $1,000 | 2016-10-02 |
| 74662 | v8 fuzzing - 1108 potential use-after-free in RegExp code | $1,000 | 2016-10-02 |
| 74660 | v8 fuzzing - 1174 - out-of-bounds write in reloc info | $1,000 | 2016-10-02 |
| 74653 | bypass SOP with blob: | $1,000 | 2016-10-02 |
| 74669 | v8 fuzzing - 1113 - stack corruption | $1,000 | 2016-10-02 |
| 74670 | v8 fuzzing 1128 - out of bounds write | $500 | 2016-10-02 |
| 74666 | v8 fuzzing 1122 - stack corruption | $1,000 | 2016-10-02 |
| 74372 | chrome://blob-internals/ xss | - | 2016-10-02 |
| 73962 | use after free due to floats not cleared (overflow) | $1,000 | 2016-10-02 |
| 74585 | Crash in CookieMonster DeleteAnyEquivalentCookie. | - | 2016-10-02 |
| 74650 | Placeholder bug for v8 security issues affecting Chrome 9 | - | 2016-10-02 |
| 74649 | OOB read in SearchBuffer::append | - | 2016-10-02 |
| 74348 | Regression: Stale node set as layout root (issue in Canvas parent layout) | - | 2016-10-02 |
| 73887 | GMail renderer crash @ MessageLoop::PostTask_Helper(tracked_objects::Location const &,Task *,__int64,bool) | - | 2016-10-02 |
| 73716 | Leak of address of heap object via xslt generate-id() function | - | 2016-10-02 |
| 73932 | Bad cast to text node in CompositeEditCommand::breakOutOfEmptyMailBlockquotedParagraph | - | 2016-10-02 |
| 73899 | Regression: Crash in RenderCombineText::combineText when running fast/text/international/text-combine-parser-test.html on Windows with full page heap enabled | - | 2016-10-02 |
| 73893 | Chrome:+Crash+Report+-+Stack+Signature:+`anonymous+namespace'::PureCall()-0ba6cf43_1414c783_9939c740_d9e6ed78_7be33815 | - | 2016-10-02 |
| 73235 | Stale pointer in WebCore::RenderBlock::lowestPosition | $1,000 | 2016-10-02 |
| 73216 | Use after free of frame loader in DocumentLoader::commitLoad | $1,000 | 2016-10-02 |
| 73526 | Floats not cleared to logical height wraps. | $1,000 | 2016-10-02 |
| 73478 | Pages can continuously poll the OS clipboard for paste data | - | 2016-10-02 |
| 73338 | Regression: stack buffer overflow in utf8 converter | - | 2016-10-02 |
| 73001 | Use-after-free in ObserverListBase / TabContents | - | 2016-10-02 |
| 73026 | dereference poisoned value in avcodec_52!ff_thread_decode_frame | - | 2016-10-02 |
| 72910 | Browser crash/segfault when selecting very long option in select | - | 2016-10-02 |
| 72908 | Freed timer heap element used | - | 2016-10-02 |
| 72832 | Reliability issues with WebCore::RenderBlock due to use after free in floats | - | 2016-10-02 |
| 73134 | Crash due to bad cast to rendertextfragment in updatefirstletter. | $1,000 | 2016-10-02 |
| 73163 | Heap corruption in safe_browsing detected on the Valgrind bot (might be fixed by SQLITE ROLL ??) | - | 2016-10-02 |
| 72936 | Freed scrollbar in ScrollView::updateScrollbars | - | 2016-10-02 |
| 72492 | Cross application unsafe redirect | $1,000 | 2016-10-02 |
| 72437 | Crash in ContainerNodeAlgorithms.h with outdated ice-tea plugin | $1,000 | 2016-10-02 |
| 72434 | stale pointer, invalid read, svg | - | 2016-10-02 |
| 72523 | chrome.tabs.captureVisibleTab allows capturing images of any "file://" resource | - | 2016-10-02 |
| 72517 | Dev. console null character crash @ history::URLDatabase::GetMostRecentKeywordSearchTerms | $500 | 2016-10-02 |
| 72399 | Valgrind reports on JPEG decoding since r74103 | - | 2016-10-02 |
| 72340 | use after free in WebCore::RenderCounter::destroyCounterNode | $1,000 | 2016-10-02 |
| 72189 | Bypass popup blocker using custom event and onMouseOver | - | 2016-10-02 |
| 72135 | IDBTransaction and IDBRequest can be deleted while ScriptExecutionContext is iterating | - | 2016-10-02 |
| 72134 | Potential buffer overrun in SVGTextRunWalker::walk() | - | 2016-10-02 |
| 72028 | Stale continuation flow pointer for ContinuationOutlineTableMap | $1,000 | 2016-10-02 |
| 71960 | OOB Read in WebGL due to integer overflows | - | 2016-10-02 |
| 72387 | Out of bounds read in WebCore::LayerTilerChromium::invalidateRect (dev only) | $1,000 | 2016-10-02 |
| 72217 | HTMLFormElement::formElementIndex() returns a bad index into a vector of form associated elements | - | 2016-10-02 |
| 71786 | ThreadSanitizer reports a race on WebCore::schemesWithUniqueOrigins (on cross_fuzz) | - | 2016-10-02 |
| 71734 | Security: accessing DataView methods with negative index could cause crash | - | 2016-10-02 |
| 71717 | webgl causes segfault | - | 2016-10-02 |
| 71601 | Switch to https by default in autofill toolbar server queries | - | 2016-10-02 |
| 71788 | Memory corruption playing back specially crafted .ogg vorbis file. | - | 2016-10-02 |
| 71763 | use-after-free when document.close and document.write are called after requesting a non-existing script | $1,000 | 2016-10-02 |
| 71855 | stale pointer in WebCore::RenderBlock::insertFloatingObject | $1,000 | 2016-10-02 |
| 71545 | Chrome_Mac: Crash Report - Stack Signature: WebKit::NotificationPresenterImpl::checkPermission-5428423 | - | 2016-10-02 |
| 71388 | Security:WebCore::HTMLTextAreaElement::updateValue+0xf | $1,000 | 2016-10-02 |
| 71386 | Stale nodes in Document::recalcStyleSelector | $1,000 | 2016-10-02 |
| 71370 | https not properly connected to google doc and gmail. | - | 2016-10-02 |
| 71357 | PPAPI var objects reference invalid memory when the instance is deleted | - | 2016-10-02 |
| 71586 | race in base/third_party/xdg_mime (crasher) | $500 | 2016-10-02 |
| 71296 | Stale iterator in SVGDocumentExtensions::startAnimations() | $1,000 | 2016-10-02 |
| 71551 | Cross_fuzz and ClusterFuzz crashes in WebCore::DatabaseTracker::removeOpenDatabase | - | 2016-10-02 |
| 71345 | fail to connect with https when browsing google doc in chrome | - | 2016-10-02 |
| 71203 | Branch ANGLE and merge fixes to m9 | - | 2016-10-02 |
| 173654 | Heap-use-after-free in WebCore::FrameSelection::notifyRendererOfSelectionChange | - | 2016-10-02 |
| 173500 | XSS: chromiumbugs.appspot.com | - | 2016-10-02 |
| 173483 | New search UI (1993) could lead to self-XSS | $500 | 2016-10-02 |
| 173402 | ASSERTION FAILED: !object || object->isRenderImage(), UNKNOWN in WebCore::HTMLAnchorElement::handleClick | - | 2016-10-02 |
| 173399 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::RenderListItem::positionListMarker | - | 2016-10-02 |
| 173397 | Heap-buffer-overflow in WTF::MemoryInstrumentation::Wrapper<WebCore::ContainerNode>::callReportMemoryUsage | - | 2016-10-02 |
| 173341 | Heap-use-after-free in content::PeerConnectionTracker::TrackSetSessionDescription | - | 2016-10-02 |
| 173250 | Security: Heap-Buffer-Overflow in extensions::SetIconNatives | - | 2016-10-02 |
| 173050 | Heap-use-after-free in WebCore::Node::removedLastRef | - | 2016-10-02 |
| 173049 | Heap-use-after-free in WebKit::WebLayerImpl::layer | - | 2016-10-02 |
| 172993 | Heap-use-after-free in WebCore::ScrollingCoordinator::hasVisibleSlowRepaintViewportConstrainedObjects | - | 2016-10-02 |
| 173068 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderFrameSet::paint | - | 2016-10-02 |
| 172926 | Heap-buffer-overflow in WebCore::AudioBufferSourceNode::process | $1,000 | 2016-10-02 |
| 172918 | Flash shouldn't load if the "src" URL has a bad content type and Content-Type-Options: nosniff | - | 2016-10-02 |
| 172824 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::commonTreeScope | - | 2016-10-02 |
| 172822 | ASSERTION FAILED: !object || object->isTextControl(), UNKNOWN in WebCore::TextControlInnerTextElement::customStyleForRenderer | - | 2016-10-02 |
| 172984 | Any MITM attacker can load NaCl :-( | - | 2016-10-02 |
| 172814 | Heap-use-after-free in WebCore::RenderTextTrackCue::layout | - | 2016-10-02 |
| 172658 | Security: TLS timing attack leading to message recovery | - | 2016-10-02 |
| 172573 | Compromised renderer can load banned plug-in | - | 2016-10-02 |
| 172342 | Heap-use-after-free in WebCore::AudioNodeInput::updateInternalBus | $1,000 | 2016-10-02 |
| 172331 | Use-after-free in WebCore::VectorMath::vsmul | $1,000 | 2016-10-02 |
| 172794 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
| 172243 | Heap-buffer-overflow in WebCore::OscillatorNode::process | $1,000 | 2016-10-02 |
| 172119 | Security: Do not allow Chrome Web Store URLs to commit in unprivileged processes | - | 2016-10-02 |
| 171962 | UNKNOWN in _wordcopy_fwd_aligned | - | 2016-10-02 |
| 171951 | Security: UAF in WebCore::SecurityOrigin::databaseIdentifier() | $1,500 | 2016-10-02 |
| 172264 | DatabaseMessageFilter: path traversal in origin_identifier | - | 2016-10-02 |
| 172071 | verify svn.golo.chromium.org subversion package is up-to-date with security fixes | - | 2016-10-02 |
| 171557 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::toRenderBox | - | 2016-10-02 |
| 171392 | Cross-Origin copy&paste / drag&drop allowing XSS (again, this time srcdoc) | - | 2016-10-02 |
| 171630 | ASSERTION FAILED: document() == newChild->document(), UNKNOWN in WebCore::ContainerNode::parserAppendChild | - | 2016-10-02 |
| 171569 | Security: Escape from NaCl sandbox on Mac OS X due to signal handler without SA_ONSTACK | - | 2016-10-02 |
| 170715 | SIGSEGV in NotificationUIManagerImpl::CancelAllBySourceOrigin() | - | 2016-10-02 |
| 171130 | Heap-use-after-free in WebCore::AXObjectCache::notificationPostTimerFired | - | 2016-10-02 |
| 170666 | Heap-use-after-free in SkAlphaRuns::add | - | 2016-10-02 |
| 171131 | Heap-use-after-free in WebCore::AccessibilityRenderObject::remoteSVGRootElement | - | 2016-10-02 |
| 170683 | Heap-use-after-free in ChromeURLDataManagerBackend::StartRequest | - | 2016-10-02 |
| 171134 | XSS in 1993 history handling | $500 | 2016-10-02 |
| 170679 | Heap-buffer-overflow in WebCore::RenderBlock::clone | - | 2016-10-02 |
| 170199 | Heap-use-after-free in WebCore::HTMLSelectElement::length | - | 2016-10-02 |
| 170240 | Heap-use-after-free in WebCore::LiveNodeListBase::invalidateCache | - | 2016-10-02 |
| 170360 | Use-after-free: Merge http://trac.webkit.org/changeset/139732 | - | 2016-10-02 |
| 170432 | UNKNOWN in WTF::equalIgnoringCase | - | 2016-10-02 |
| 170237 | Heap-use-after-free in WebCore::InspectorInstrumentation::didHandleEventImpl | - | 2016-10-02 |
| 170188 | Heap-use-after-free in WebCore::Document::updateHoverActiveState | - | 2016-10-02 |
| 169973 | IPC: out-of-bounds vector accesses with mismatched vector | - | 2016-10-02 |
| 169972 | Security: Heap-Buffer-Overflow in usb_api.cc:CreateBufferForTransfer | - | 2016-10-02 |
| 169966 | IPC: negative integer in command to safe browsing host will cause bad vector access | - | 2016-10-02 |
| 169770 | IPC: Unvalidated content type used as index for write into raw array | - | 2016-10-02 |
| 169765 | Security: Integer overflow in libusb_alloc_transfer causes Heap-Buffer-Overflow in chrome.usb.isochronousTransfer | - | 2016-10-02 |
| 170184 | Heap-buffer-overflow in WebCore::RenderTableSection::nodeAtPoint | - | 2016-10-02 |
| 170034 | Security: ASAN issue in chromeos::VersionInfoUpdater::OnBootTimes() | - | 2016-10-02 |
| 169981 | Security: chrome.usb Api missing parameter validation for "length" | - | 2016-10-02 |
| 169723 | [LangFuzz] Crash at v8::internal::AccessorPair::GetComponent with invalid read | $1,000 | 2016-10-02 |
| 71115 | Stale pointer in WebCore::RenderTable::firstLineBoxBaseline | $1,000 | 2016-10-02 |
| 71114 | Stale pointer due to table childs incorrect added | $1,000 | 2016-10-02 |
| 71167 | Bypass popup blocker using custom event (variation of issue 3275) | - | 2016-10-02 |
| 70877 | Arbitrary cross-origin bypass using SyntaxError and Number prototype overrides | $1,337 | 2016-10-02 |
| 70819 | Empty address bar after opening an URL from extension in new tab | - | 2016-10-02 |
| 70779 | width of boundingClientRect for Range with unicode combining characters is corrupted | - | 2016-10-02 |
| 70718 | crashes when opening a page with webgl | - | 2016-10-02 |
| 70589 | race on a linked list in third_party/WebKit/Source/WebCore/platform/sql/chromium/SQLiteFileSystemChromiumPosix.cpp | - | 2016-10-02 |
| 71027 | REGRESSION: crash after download and close window (only in incognito) | - | 2016-10-02 |
| 70885 | Bypass popup blocker using iframe | - | 2016-10-02 |
| 70456 | OOM handler not always properly terminating process | $1,000 | 2016-10-02 |
| 70538 | Open popup in new tab using java applet | - | 2016-10-02 |
| 70374 | Browser crash: DeterminePossibleFieldTypesForUpload | - | 2016-10-02 |
| 70577 | Security: webgl crashes on all tabs + processing spike even after all webgl programs are closed | - | 2016-10-02 |
| 70376 | Pickle::FindNext reads payload_size without checking that the header is complete | - | 2016-10-02 |
| 70244 | height of <rect> - integer overflow(?) | $1,000 | 2016-10-02 |
| 70337 | Regression: new window.onerror() implementation leaks cross-origin Javascript errors | - | 2016-10-02 |
| 70070 | WebGL crashes depending on uniform names | $500 | 2016-10-02 |
| 70231 | Prefetch: Do not present authentication prompt | - | 2016-10-02 |
| 70336 | Cross-origin Javascript error message leak via Worker importScripts() | $500 | 2016-10-02 |
| 70078 | Crash by form controls with form attributes under orphan nodes | $500 | 2016-10-02 |
| 69934 | Use after free in LayoutPluginTester.SelfDeletePluginInvoke | - | 2016-10-02 |
| 69825 | security flaw | - | 2016-10-02 |
| 69970 | Invalid read in convertV8ObjectToNPVariant | - | 2016-10-02 |
| 70027 | Stale text node in linebox due to failure to dirty linebox when that text child is dirtied | $1,000 | 2016-10-02 |
| 69965 | Use after free in geolocation infobars | - | 2016-10-02 |
| 69628 | Probable memory corruption in WebCore::CounterNode::lastDescendant | $500 | 2016-10-02 |
| 69597 | Segfault in WebCore::ContainerNode::removeAllChildren() | - | 2016-10-02 |
| 69569 | Crashed @ IPC::Channel::ChannelImpl::OnIOCompleted when delete browser history | - | 2016-10-02 |
| 69657 | Not signing out from my https webmail account. | - | 2016-10-02 |
| 69531 | Valgrind/Memcheck reports uninitialized use of SkGlyph::fMaskFormat in third_party/skia/src/core/SkScalerContext.cpp | - | 2016-10-02 |
| 69640 | memcheck: read after free in third_party/icu/source/common/unormimp.h | - | 2016-10-02 |
| 69556 | Issue with merging anonymous block in renderblock::removechild (2) | $1,000 | 2016-10-02 |
| 69275 | Use after free in scrollbars | - | 2016-10-02 |
| 69187 | Error prototypes are called on remote scripts | $1,337 | 2016-10-02 |
| 69159 | Crash @ PasswordStore::RemoveLogin | - | 2016-10-02 |
| 69106 | ZDI-CAN-1009: Apple Webkit setOuterText Memory Corruption Remote Code Execution Vulnerability | - | 2016-10-02 |
| 69294 | Browser crash when executing indexedDb tutorial.html in an incognito window. | - | 2016-10-02 |
| 69195 | playing Z-Type causes crash | - | 2016-10-02 |
| 68741 | Stale pointers in CSSOM - 2 | $1,000 | 2016-10-02 |
| 68646 | Integer overflow and signed comparison in RenderView::DidDownloadApplicationIcon() | - | 2016-10-02 |
| 68641 | Stale form associated element pointer in Document object | $1,000 | 2016-10-02 |
| 68773 | Chrome: Crash Report - Stack Signature: UTF8ToUTF16(std::basic_string<char,std::char_traits<char>,std::allocator<char> > const &)-382777c6_d21c627c_9e383e89_c1eaa2f5_ef047e8d | - | 2016-10-02 |
| 68766 | Chrome: Crash Report - Stack Signature: net::HttpStreamFactory::~HttpStreamFactory()-2A77B8F | - | 2016-10-02 |
| 68434 | Search Bug Dynamic dns | - | 2016-10-02 |
| 68369 | Installing extensions in "popup"-type windows crash browser | - | 2016-10-02 |
| 68342 | Aw snap on github.com with voice search extension installed | $500 | 2016-10-02 |
| 68439 | Destroying nextblock in RenderBlock::removeChild can cause oldChild and nextblock's next sibling to be merged. | $1,000 | 2016-10-02 |
| 68244 | Playing audio with volume set to undefined crashes browser | - | 2016-10-02 |
| 68170 | invalid free() in bundled pdf viewer | $1,000 | 2016-10-02 |
| 68259 | Virus, exploit in maps | - | 2016-10-02 |
| 68130 | Memory corruption in font draws for accelerated 2d canvas. | - | 2016-10-02 |
| 68115 | Memory corruption with bad Vorbis streams (from CERT) | $1,000 | 2016-10-02 |
| 68075 | chrome.dll!WebCore::CounterNode::resetRenderers ExecAV@NULL (7b931db52815b50413964fbdd401fe15) | - | 2016-10-02 |
| 68062 | OOB read crash in SVG length list parsing algorithm | - | 2016-10-02 |
| 67968 | Use after free due to adjacent floats not cleared properly from parents | - | 2016-10-02 |
| 67966 | the bank tell me my browser ar not safe | - | 2016-10-02 |
| 67923 | Stale pointer in SVGImage | - | 2016-10-02 |
| 68120 | Stale pointer in CSSFontFaceSource::m_svgFontFaceElement | $1,000 | 2016-10-02 |
| 177913 | Heap-buffer-overflow in AutofillExternalDelegate::OnSuggestionsReturned | - | 2016-10-02 |
| 177876 | Heap-use-after-free in webkit::ppapi::PPB_URLLoader_Impl::FillUserBuffer | - | 2016-10-02 |
| 177858 | Global-buffer-overflow in v8::internal::MaybeObject* v8::internal::SlowQuoteJsonString<unsigned char, v8::internal::SeqOneByte | - | 2016-10-02 |
| 177932 | Heap-use-after-free in WebCore::SVGElementInstance::invalidateAllInstancesOfElement | - | 2016-10-02 |
| 177873 | Security: out of bounds write with webgl and gl.DEPTH_COMPONENT | $1,000 | 2016-10-02 |
| 177688 | ASSERTION FAILED: obj->isRenderInline() || obj == this, Bad cast in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
| 177620 | Heap-use-after-free in WebCore::HTMLMediaElement::~HTMLMediaElement | $1,000 | 2016-10-02 |
| 177410 | Heap-use-after-free in extensions::BookmarksIOFunction::ShowSelectFileDialog | - | 2016-10-02 |
| 177403 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::RenderBlock::clone | - | 2016-10-02 |
| 177737 | Heap-use-after-free in webrtc::DataChannel::Send | - | 2016-10-02 |
| 177686 | Heap-use-after-free in WebCore::ImageLoader::dispatchPendingErrorEvent | - | 2016-10-02 |
| 177815 | pepper_flash_clipboard_message_filter.cc assumed same-sized vectors from untrusted Flash process | - | 2016-10-02 |
| 176882 | Heap-use-after-free in WebCore::FrameLoader::checkCompleted | $1,000 | 2016-10-02 |
| 176863 | ASSERTION FAILED: !detachingNode, Heap-buffer-overflow in WebCore::CSSImageGeneratorValue::removeClient | - | 2016-10-02 |
| 177215 | ASSERTION FAILED: static_cast<unsigned>(m_start + length) <= string.length(), UNKNOWN in WebCore::InlineTextBox::paint | - | 2016-10-02 |
| 176719 | Global-buffer-overflow in cld::ProcessProbV25UniTote | - | 2016-10-02 |
| 176692 | postTaskForModeToWorkerContext/dispatchTaskToWorkerThread invalid pointer crash with Workers/FileSystem API | $1,000 | 2016-10-02 |
| 177197 | Heap-buffer-overflow in void WTF::Vector<unsigned short, 1024ul>::insert<unsigned short> | - | 2016-10-02 |
| 176738 | ASSERTION FAILED: itemIndex < m_values->size(), UNKNOWN in WebCore::SVGPathSegListPropertyTearOff::processIncomingListItemValue | - | 2016-10-02 |
| 176514 | Heap-use-after-free in WebCore::RenderObject::propagateStyleToAnonymousChildren | - | 2016-10-02 |
| 176298 | Heap-buffer-overflow in std::_Rb_tree<int, int, std::_Identity<int>, std::less<int>, std::allocator<int> >::erase | - | 2016-10-02 |
| 176252 | RenderViewHostImpl::OnMessageReceived | $1,000 | 2016-10-02 |
| 176137 | Data extraction with XSS Auditor | $500 | 2016-10-02 |
| 176676 | Heap-use-after-free in cricket::TransportChannelProxy::SetImplementation | - | 2016-10-02 |
| 176033 | Use-after-free in webrtc::WebRtcSession::data_channel() | - | 2016-10-02 |
| 176027 | Heap-buffer-overflow in SkARGB32_Opaque_Blitter::blitMask | - | 2016-10-02 |
| 175741 | UNKNOWN in webkit::ppapi::PluginInstance::PrintPDFOutput | - | 2016-10-02 |
| 175343 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::AccessibilityMenuListPopup::didUpdateActiveOption | - | 2016-10-02 |
| 175342 | Heap-use-after-free in WebCore::DeleteButtonController::enable | - | 2016-10-02 |
| 175305 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
| 176056 | Global-buffer-overflow in v8::internal::MarkCompactCollector::EmptyMarkingDeque | - | 2016-10-02 |
| 174920 | Heap-use-after-free in WebCore::CachedCSSStyleSheet::checkNotify | - | 2016-10-02 |
| 174676 | Heap-use-after-free in SpellcheckHunspellDictionary::InitializeDictionaryLocation | - | 2016-10-02 |
| 174846 | Heap-use-after-free in WebCore::ElementRuleCollector::collectMatchingRulesForList | - | 2016-10-02 |
| 175069 | Heap-use-after-free in net::SpdySession::DoLoop | - | 2016-10-02 |
| 174895 | IndexedDB: missing check that index_ids and index_keys have equal size | - | 2016-10-02 |
| 174566 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::SVGListProperty<WebCore::SVGPathSegList>::replaceItemValues | - | 2016-10-02 |
| 174328 | IndexedDB: overflow of 2-bit index id size field | - | 2016-10-02 |
| 174146 | Crashing in gpu::gles2::GLES2Implementation::ReadPixels(int,int,int,int,unsigned int,unsigned int,void *) | - | 2016-10-02 |
| 174137 | Crashing in WebCore::ChannelMergerNode::process(unsigned int) | - | 2016-10-02 |
| 174129 | Security: Silent HTTP Basic Authentification & HTTP Authentification Brute Force | - | 2016-10-02 |
| 174579 | stack-buffer-overflow in ui::ScrollEvent::Scale on Chrome OS | - | 2016-10-02 |
| 174150 | Crashing in media::VideoRendererBase::ThreadMain() | - | 2016-10-02 |
| 174020 | ASSERTION FAILED: !object || object->isMenuList(), UNKNOWN in WebCore::HTMLSelectElement::menuListDefaultEventHandler | - | 2016-10-02 |
| 173906 | document.referrer leakage with XSS Auditor page block | - | 2016-10-02 |
| 173880 | Heap-buffer-overflow in media::OpusAudioDecoder::ConfigureDecoder | - | 2016-10-02 |
| 174049 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderTableSection::layout | - | 2016-10-02 |
| 174017 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::SVGAnimationElement::currentValuesForValuesAnimation | - | 2016-10-02 |
| 173781 | Heap-buffer-overflow in void std::__introsort_loop<WebCore::GridTrack**, long, bool | - | 2016-10-02 |
| 173688 | Security: Non-web-accessible extension URLs should not load in non-extension processes | - | 2016-10-02 |
| 67393 | Freeing invalid uninitialized pointer to bug_report_ object | $1,000 | 2016-10-02 |
| 67363 | EXTERNAL-REPORT: SVGElementInstance::m_useElement not cleared on corresponding use element destruction | $500 | 2016-10-02 |
| 67577 | Switch .jar and .class to always-warn | - | 2016-10-02 |
| 67234 | Webkit crashes during animation event processing | - | 2016-10-02 |
| 67303 | renderer crash when playing a corrupt webm video | $1,000 | 2016-10-02 |
| 67208 | VU#821271 Exception generated by code running in the Stack | $1,000 | 2016-10-02 |
| 66986 | Reparenting error due to double merge of anonymous blocks in removeChild | - | 2016-10-02 |
| 66962 | browser crash when reproducing issue #64051 | - | 2016-10-02 |
| 66931 | Google Chrome crashes at https://webmail.afmc.af.mil/Exchange | - | 2016-10-02 |
| 66841 | Chrome View keeps changing percentage(decreasing to 50%) automatically | - | 2016-10-02 |
| 67100 | Crash in PDF form event handling when deleting page from underneath self | - | 2016-10-02 |
| 66760 | ZDI-CAN-968: Apple Webkit Font Glyph Layout Remote Code Execution Vulnerability | - | 2016-10-02 |
| 66718 | webgl page causes X server crash | - | 2016-10-02 |
| 66700 | chrome.dll!WebCore::RenderTextControlSingleLine::speechAttributeChanged ReadAV@NULL (7acb553d23eecf733d9ececf57a499f7) | - | 2016-10-02 |
| 66676 | REGRESSION: Crash on exit after clearing all downloads | - | 2016-10-02 |
| 66486 | MAC OSX 10.6.5 google chrome | - | 2016-10-02 |
| 66473 | Crash in ReplaceSelectionCommand::doApply when modified during mutation event | - | 2016-10-02 |
| 66748 | CSSCursorImageValue not clearing SVGElement back pointer | $500 | 2016-10-02 |
| 66334 | Crashes at wild EIP when pressing "print" button on PDFs | - | 2016-10-02 |
| 65942 | Stale pointer in Range::processContents when modified during mutation event | - | 2016-10-02 |
| 65869 | crash when rapidly reloading a page with an applet | - | 2016-10-02 |
| 65845 | Bad cast from RenderText to RenderBox due to details tag being shown inline. | - | 2016-10-02 |
| 65796 | Children of cloned anonymous blocks should set childreninline flag | - | 2016-10-02 |
| 65299 | Out of bound read when using modified webp file | $500 | 2016-10-02 |
| 65194 | Renderer crash @ gpu::gles2::GLES2Implementation::TexSubImage2D(unsigned int,int,int,int,int,int,unsigned int,unsigned int,void const *) | - | 2016-10-02 |
| 64974 | Integer overflow leading to OOB read, possible memory corruption in webgl getfloat32 | - | 2016-10-02 |
| 64949 | Crash with progressive rendering | - | 2016-10-02 |
| 64788 | Access data from my company Google Docs (domain wittit.com) with my gmail account. | - | 2016-10-02 |
| 64669 | Not allow overwrite of field data when merging profile data | - | 2016-10-02 |
| 64559 | Bad cast when selection changes for combo boxes. | - | 2016-10-02 |
| 64456 | Chrome crashes when attempting to install a userscript. | - | 2016-10-02 |
| 64945 | Crash when webp image is invalid | $1,000 | 2016-10-02 |
| 64364 | falla al inicio de abrir el navegador | - | 2016-10-02 |
| 64331 | Stale node being set as layout root when rendering meter, progress elements. | - | 2016-10-02 |
| 64088 | Use after free due to calling a stale timer on a closed frame/document | - | 2016-10-02 |
| 64046 | WebKit 49902 - chrome.dll!WebCore::toWebWidgetClient ReadAV@NULL (08ffd4f21a8c6465bb1e19a2f52e4bd5) | - | 2016-10-02 |
| 63982 | Memory corruption in RenderObjectChildList::removeChildNode | - | 2016-10-02 |
| 64424 | Computing style on a stale node while sending pending accessibility notification | - | 2016-10-02 |
| 64108 | Verify cross-origin push fails under SPDY | - | 2016-10-02 |
| 63911 | Memory corruption in accelerated 2d canvas | - | 2016-10-02 |
| 63945 | More memory corruption in accelerated 2d canvas, this time in moveTo | - | 2016-10-02 |
| 63617 | Closing multiple WebGL tabs at the same time causes segfault in Xorg | - | 2016-10-02 |
| 63609 | Delete any link promotes - Orkut OLD | - | 2016-10-02 |
| 63552 | Windows media player plugin crashes all the time @ NPAPI::PluginLib::Load+0x116 | - | 2016-10-02 |
| 63533 | WebM Crash fix merge from M7 | - | 2016-10-02 |
| 63529 | Security: Segfault when dealing with Web Workers and MessageChannels | - | 2016-10-02 |
| 63866 | WebKit CSS Font Face Parsing Type Confusion | $1,000 | 2016-10-02 |
| 63924 | Bad cast from RenderTableCol to RenderBlock in search css | - | 2016-10-02 |
| 63732 | Browser crash @ JavaScriptAppModalDialog::Cleanup() | $500 | 2016-10-02 |
| 63389 | Setting small numeric CSS values using setFloatValues changes that value on all pages until the browser is quit | - | 2016-10-02 |
| 63268 | Universal XSS via mutating style objects and read styles cross origins | - | 2016-10-02 |
| 63248 | segfault in bundled PDF viewer (invalid read in strlen) | $1,000 | 2016-10-02 |
| 63444 | Security: possible memory corruption (double-free) in XPath processing code | $1,000 | 2016-10-02 |
| 63495 | WebCore::NamedNodeMap::setAttributes() stale iterator | - | 2016-10-02 |
| 63454 | Analyze integer wraps in WebCore::Range. | - | 2016-10-02 |
| 63380 | SVG Transformlist memory corruption | - | 2016-10-02 |
| 63031 | Stale font accessed in WebCore::GlyphPage::glyphDataForCharacter | - | 2016-10-02 |
| 63166 | CryptUnprotectData disclose sensitive information in stack | - | 2016-10-02 |
| 63051 | chrome_6dc70000!WebCore::EventHandler::updateSelectionForMouseDrag use after free | $500 | 2016-10-02 |
| 63037 | Security: chrome.google.com Stored XSS | - | 2016-10-02 |
| 189090 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
| 189089 | ASSERTION FAILED: curr->isRenderBlock(), UNKNOWN in WebCore::RenderBlock::splitBlocks | - | 2016-10-02 |
| 189250 | Security: pango loads config options from $HOME/.pangorc | - | 2016-10-02 |
| 189091 | Heap-use-after-free in extensions::ObjectBackedNativeHandler::Router | - | 2016-10-02 |
| 189084 | Bad cast in WebKit::WebPageSerializerImpl::endTagToString | - | 2016-10-02 |
| 187243 | Heap-use-after-free in WebCore::InlineBox::deleteLine | - | 2016-10-02 |
| 181617 | Security: Possible path traversal in file_util::AbsolutePath (Windows XP/2K3) | $1,337 | 2016-10-02 |
| 181580 | Heap-use-after-free in extensions::ModuleSystem::LazyFieldGetterInner | - | 2016-10-02 |
| 187245 | Heap-use-after-free in SkTypeface::getTableSize | - | 2016-10-02 |
| 188092 | Invalid pointer read in WebCore::WaveShaperProcessor::process | - | 2016-10-02 |
| 183741 | arbitrary number of popups in response to single user action | - | 2016-10-02 |
| 181083 | Security: H.264 scaling list parsing overflow | $40,000 | 2016-10-02 |
| 180920 | Heap-use-after-free in WebCore::ElementRuleCollector::collectMatchingRulesForList | - | 2016-10-02 |
| 181438 | TransportDIB::Map doesn't validate size of mapped section on Windows | - | 2016-10-02 |
| 180763 | PWN2OWN: Bad cast in SVGViewSpec::viewTarget | - | 2016-10-02 |
| 180593 | Heap-use-after-free in WebCore::RenderBlock::logicalRightOffsetForLine | - | 2016-10-02 |
| 180555 | Security: DevTools renderer navigation is handled in renderer and allows opening any URL in DevTools window. | - | 2016-10-02 |
| 181375 | Heap-use-after-free in WebCore::AXObjectCache::getOrCreate | - | 2016-10-02 |
| 180909 | Buffer overflow in URLLoader::ReadResponseBodyAck | - | 2016-10-02 |
| 180051 | Use after free in PersistentTabRestoreService (during shutdown?) | - | 2016-10-02 |
| 179653 | ANGLE shader compiler: struct size overflow | - | 2016-10-02 |
| 179634 | Heap-use-after-free in (anonymous | - | 2016-10-02 |
| 179632 | Heap-use-after-free in sigslot::_signal_base1<bool, sigslot::single_threaded>::disconnect | - | 2016-10-02 |
| 179631 | Heap-use-after-free in WebCore::SegmentedString::SegmentedString | - | 2016-10-02 |
| 179580 | Devtools uses dangling WebContents* when extension reloads | - | 2016-10-02 |
| 180058 | Security: Loading NaCl from Web via permissive extension | - | 2016-10-02 |
| 179654 | ANGLE shader compiler: validate numBytes in TPoolAllocator::allocate | - | 2016-10-02 |
| 178848 | Chrome_Linux: Crash Report - Stack Signature: extensions::UserScriptSlave::GetDataSourceU... | - | 2016-10-02 |
| 178706 | Mac AVCConfigRecordBuilder: integer overflow leading to heap-buffer-overflow | - | 2016-10-02 |
| 178780 | Security: Chrome extensions whitelist leaks IDs | - | 2016-10-02 |
| 178761 | Heap-use-after-free in WebCore::FrameView::maintainScrollPositionAtAnchor | - | 2016-10-02 |
| 178760 | Heap-use-after-free in gtk_floating_container_add_floating | - | 2016-10-02 |
| 179287 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::RenderSliderContainer::layout | - | 2016-10-02 |
| 179522 | Heap-use-after-free in WebCore::AudioNodeOutput::pull | $3,133 | 2016-10-02 |
| 178797 | Use-after-free under CachedRawResource::responseReceived | - | 2016-10-02 |
| 178266 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 178242 | NavigationController can copy wrong NavigationEntry when committing a new page | - | 2016-10-02 |
| 178269 | Heap-use-after-free in WebCore::FrameLoader::stopForUserCancel | - | 2016-10-02 |
| 178130 | ASSERTION FAILED: node->treeScope() == m_oldScope, Heap-use-after-free in WebCore::TreeScopeAdopter::moveTreeToNewScope | - | 2016-10-02 |
| 178581 | Heap-use-after-free in BrowsingDataRemover::DoClearCache | - | 2016-10-02 |
| 178264 | Heap-use-after-free in WebCore::Frame::setPageAndTextZoomFactors | - | 2016-10-02 |
| 178002 | Heap-use-after-free in WebCore::LiveNodeList::namedItem | - | 2016-10-02 |
| 177933 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::SVGAnimatedTransformListAnimator::calculateAnimatedValue | - | 2016-10-02 |
| 178003 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::HTMLElementStack::popCommon | - | 2016-10-02 |
| 177956 | cross-process memory address leak via sa_restorer | $1,000 | 2016-10-02 |
| 62987 | Use after free in EventSource | - | 2016-10-02 |
| 62925 | <Unloaded_S.DLL>+0x42cd17f crash | $1,000 | 2016-10-02 |
| 62718 | renderer crash in PDF viewer (possibly due to overlapping memcpy) | - | 2016-10-02 |
| 62674 | Valgrind detected invalid read in net::SingleRequestHostResolver::Cancel() - use-after-free? | - | 2016-10-02 |
| 62623 | Crash at NULL IP in PDF when evaluating strange expression | $1,000 | 2016-10-02 |
| 62401 | Crash in WebCore::SMILTimeContainer::begin | $1,000 | 2016-10-02 |
| 62358 | Integer overflow in SVG Parsing | - | 2016-10-02 |
| 62791 | Crash loading invalid crx extension file | - | 2016-10-02 |
| 62354 | Bad cast in SVGImageBufferTools::renderSubtreeToImageBuffer | - | 2016-10-02 |
| 62296 | Bad cast from renderinline to renderbox in animations | - | 2016-10-02 |
| 62281 | Use after free due to overhanging floats in LEGEND block | - | 2016-10-02 |
| 62276 | Out of bound memory access in webp decoder | - | 2016-10-02 |
| 62261 | use after free in ContainerNode::willRemove | - | 2016-10-02 |
| 62168 | Bad cast in WebDevToolsFrontendImpl::dispatchOnInspectorFrontend | - | 2016-10-02 |
| 62158 | Exploitable-looking crash when simply selecting a drop-down value | - | 2016-10-02 |
| 62293 | Bad cast in CSSStyleSelector::createTransformOperations | - | 2016-10-02 |
| 62118 | Autosave - Password | - | 2016-10-02 |
| 61975 | Page is shown before password is requested | - | 2016-10-02 |
| 61919 | [Regression] Browser crash in GetMostVisitedThumbnailsOnDBThread | - | 2016-10-02 |
| 61917 | [Regression] Purecall in TopSitesDatabase::UpdatePageThumbnail | - | 2016-10-02 |
| 62127 | faulty webm file causes segfault | $1,000 | 2016-10-02 |
| 61954 | split webstorePrivate.install into two functions, one of which requires a gesture | - | 2016-10-02 |
| 61719 | Chrome | - | 2016-10-02 |
| 61691 | SECURITY FAIL | - | 2016-10-02 |
| 61653 | MSVR-10-0108 - Integer Overflow in Chrome's VP8 decoding leads to memory corruption | - | 2016-10-02 |
| 61634 | webstorePrivate.install method should not suppress install confirmation for extensions with NPAPI | - | 2016-10-02 |
| 61721 | Security: Google Chrome 7.0.517.41 Multiple DLL Hijacking Vulnerability | - | 2016-10-02 |
| 61701 | Security: google chrome crashes when a request passes through a proxy and recieves a 407 HTTP error code from the server | - | 2016-10-02 |
| 61848 | Search results are displayed in bing. | - | 2016-10-02 |
| 61555 | on double click of a password with comma in it, selects only the part separated by comma instead of selecting fully. The compromises security besides being an inconvenience. | - | 2016-10-02 |
| 61502 | Floats left out of the incremental line break code due to failed image load. | - | 2016-10-02 |
| 61338 | pdf viewer segfault after js syntax error | $1,000 | 2016-10-02 |
| 61577 | Security Bug: Google Docs Published Spreadsheets | - | 2016-10-02 |
| 61255 | Bad cast in PageClickTracker::handleEvent | - | 2016-10-02 |
| 61576 | WebKit 48831 - chrome.dll!WebCore::SVGLength::SVGLength WriteAV@Arbitrary (ab566cfad36b72d82883e59d51a1dbec) | - | 2016-10-02 |
| 61313 | Use after free related to ApplyBlockElementCommand::formatSelection | - | 2016-10-02 |
| 61129 | Double click selection behaviour exposes password information | - | 2016-10-02 |
| 60978 | WebGL stencil buffers not correctly initialized | - | 2016-10-02 |
| 60816 | Crash in hunspell::NodeReader::FindWord | - | 2016-10-02 |
| 60769 | more bad casts in event handling. | - | 2016-10-02 |
| 60761 | chrome_1c30000!TabContents::RemoveInfoBar(class InfoBarDelegate * delegate = 0x05dfe700)+0x1dfull tab crash | - | 2016-10-02 |
| 61158 | Use after free in ApplyStyleCommand::removeInlineStyle | - | 2016-10-02 |
| 60695 | Bad cast in RenderView docheight,docwidth calc due to adding non box childs | - | 2016-10-02 |
| 60688 | chrome_55000000!WebCore::FEBlend::apply+0x1a5 | $1,000 | 2016-10-02 |
| 60653 | Memory error inside WTF::String::format | - | 2016-10-02 |
| 60496 | Speed tracer + AdBlock = Renderer Crash @ v8::internal::Invoke | - | 2016-10-02 |
| 60327 | Bad cast to MouseEvent in Node::defaultEventHandler() | $500 | 2016-10-02 |
| 60238 | Use after free of m_frame in FrameLoader::loadWithDocumentLoader | $500 | 2016-10-02 |
| 60697 | CSS, background-repeat bug | - | 2016-10-02 |
| 60029 | OOB read with StringImpl::find line 621 | - | 2016-10-02 |
| 59817 | Security: Add .html and .htm to the dangerous extensions list for OSX and OS_POSIX | - | 2016-10-02 |
| 60055 | WebM crash in vp8_setup_intra_recon() | $1,000 | 2016-10-02 |
| 59663 | CSSPrimitiveValue::cssText() may cause a buffer overflow | - | 2016-10-02 |
| 60013 | RenderIndicator childs not laid out at all. | - | 2016-10-02 |
| 223145 | Security: <template> implementation fails to check for "template" in special list when handling "any other end tag for in body" | - | 2016-10-02 |
| 223125 | Heap-buffer-overflow in WebCore::InlineIterator::atTextParagraphSeparator | - | 2016-10-02 |
| 223032 | ASSERTION FAILED: !HashTranslator::equal(Extractor::extract(deletedValue), key), Heap-buffer-overflow in WebCore::Font::width | - | 2016-10-02 |
| 222852 | Heap-use-after-free in WebCore::RenderObject::isDescendantOf | - | 2016-10-02 |
| 222770 | UNKNOWN in WebCore::QualifiedName* WTF::HashTable<WebCore::QualifiedName, WebCore::QualifiedName, WTF::Identity | - | 2016-10-02 |
| 222754 | Multiple ffmpeg security issues found by j00ru. | - | 2016-10-02 |
| 222539 | UNKNOWN in WTF::Vector<WTF::Vector<WebCore::RenderBox*, 1ul>, 0ul>::reserveCapacity | - | 2016-10-02 |
| 223034 | Heap-buffer-overflow in void media::ToInterleavedInternal<int, long> | - | 2016-10-02 |
| 223238 | Heap-use-after-free in GIFImageReader::decode | $1,000 | 2016-10-02 |
| 222000 | Use after free - using speech API after loading a web page | $1,000 | 2016-10-02 |
| 222036 | Heap-use-after-free in cricket::WebRtcRenderAdapter::FrameSizeChange | - | 2016-10-02 |
| 222136 | Heap-use-after-free in WebCore::AudioDSPKernelProcessor::reset | - | 2016-10-02 |
| 221131 | HTML tags are not sanitized in chrome://network | - | 2016-10-02 |
| 220039 | Security: Chrome extensions can manipulate Chrome sign-in screen | - | 2016-10-02 |
| 219175 | Security: uid and gid 233 double-allocated to tlsdate-dbus and debugd-logs users/group in Chrome OS ToT | - | 2016-10-02 |
| 216501 | enable manifest checking in chromiumos-overlay | - | 2016-10-02 |
| 217858 | [LangFuzz] Crash on Heap with invalid read (possibly due to uninitialized value) on 64 bit | $1,000 | 2016-10-02 |
| 214314 | Enable GPU process seccomp filter sandbox on Chrome OS | - | 2016-10-02 |
| 214730 | Security: Remove "--enable-nacl" on daisy/snow boards before production | - | 2016-10-02 |
| 209604 | Heap-use-after-free in WebCore::RenderObject::container | $1,000 | 2016-10-02 |
| 213970 | Seccomp filter for avfsd on ARM | - | 2016-10-02 |
| 203443 | use-after-free in views::View::parent() from chromeos::BalloonContainer::HasBalloonView() | - | 2016-10-02 |
| 204504 | minijail ignores user/group id and runs as root when it can't find /lib/minijailpreload.so | - | 2016-10-02 |
| 196575 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderFrameSet::fillFromEdgeInfo | - | 2016-10-02 |
| 196571 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::Element::offsetParent | - | 2016-10-02 |
| 196570 | ASSERTION FAILED: !object || object->isCanvas(), UNKNOWN in WebCore::AccessibilityRenderObject::computeAccessibilityIsIgnored | - | 2016-10-02 |
| 196456 | Any web site can launch Google Talk plug-ins (either of them) by fiddling with ':' in URL syntax | - | 2016-10-02 |
| 196648 | IPC: destroy routes for video decoders on GpuCommandBufferStub destruction | - | 2016-10-02 |
| 196174 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::HTMLTreeBuilder::resetInsertionModeAppropriately | - | 2016-10-02 |
| 196071 | Security: XMLHttpRequest HTTP Referer Header Faking | - | 2016-10-02 |
| 194749 | REGRESSION: Chrome crashed while launching Bejeweled game | - | 2016-10-02 |
| 193197 | Security: Overflow READING BlueZ adapter's config from /var/lib on startup | - | 2016-10-02 |
| 196393 | RIP == 0 in WebCore::StyleResolver::matchAllRules | $1,000 | 2016-10-02 |
| 59627 | Renderer crash while profiling @ v8::internal::Context::global_context() | - | 2016-10-02 |
| 59625 | GPU ANGLE Preprocessor Extension Stack Overflow | - | 2016-10-02 |
| 59623 | GPU ANGLE Symbol Parsing Multiple Stack Overflows | - | 2016-10-02 |
| 59593 | Stale pointer in WebCore::ThreadTimers::sharedTimerFiredInternal | - | 2016-10-02 |
| 59584 | repaired | - | 2016-10-02 |
| 59554 | Use after free when encountering history.back() call during Page::goToItem execution | $500 | 2016-10-02 |
| 59504 | WebGL Context GPU Channel Dangling Pointer | - | 2016-10-02 |
| 59320 | Segfault in x86_64/memset.S below SkScalerContext::getImage on Linux | $1,000 | 2016-10-02 |
| 59314 | [Merge] Blob / BlobBuilder can be put into bad state with wild integers and strings, due to integer overflows | - | 2016-10-02 |
| 59036 | PDF JS engine doesn't work in 64 bit | $1,337 | 2016-10-02 |
| 58829 | Memory corruption in SyncChannel::SyncContext::OnChannelClosed() | - | 2016-10-02 |
| 59081 | Security: do not allow on-page drag-and-drop from non-same-origin frames (or require an extra gesture) | - | 2016-10-02 |
| 58731 | Invalid memory access (with possible avenue to corruption) in the xpath handling libxml | $1,000 | 2016-10-02 |
| 58657 | Bad cast on SVG use element due to mismatched shadow and instance pointers | $1,000 | 2016-10-02 |
| 58741 | Use after free in HTMLTextFormControlElement::selection() | $500 | 2016-10-02 |
| 58319 | Browser crash - creating unlimited number of File Dialogs | - | 2016-10-02 |
| 58008 | Bad cast casting parent class obj InlineFlowBox to child class obj RootInlineBox | - | 2016-10-02 |
| 57743 | Stale pointer in WebSocket connection handshake | - | 2016-10-02 |
| 57691 | Security Bug: Uploading without ever choosing to upload | - | 2016-10-02 |
| 58053 | Crash in BallonViewImpl::DelayedClose() | - | 2016-10-02 |
| 57908 | build with -fPIE | - | 2016-10-02 |
| 58069 | Windows Sandbox allows access to the console. | - | 2016-10-02 |
| 57501 | Crash in PDF plugin when building cross-refs | $500 | 2016-10-02 |
| 57377 | Cross origin bypass with CSS getMatchedCSSRules() | - | 2016-10-02 |
| 57347 | ZDI-CAN-874: Apple Webkit WholeText Integer Overflow Remote Code Execution Vulnerability | - | 2016-10-02 |
| 57200 | Use after free from accessing stale renderers in m_floatingObjects in lowestPosition | - | 2016-10-02 |
| 57002 | abcd | - | 2016-10-02 |
| 56996 | Renderer crash when navigating between Field and Aquarium @ WebCore::Node::detach() | - | 2016-10-02 |
| 56993 | Form data is not cleared or even offered in the "Clear browser history" | - | 2016-10-02 |
| 57083 | Possible bug with Chrome and PayPal | - | 2016-10-02 |
| 56760 | segfault in bundled pdf viewer | $1,000 | 2016-10-02 |
| 57080 | remove extension renaming code | - | 2016-10-02 |
| 56796 | Bad cast in casting CSSInitialValue to SVGColor in css | - | 2016-10-02 |
| 56692 | Bad cast from RenderInline to RenderBox in positionListMarker | - | 2016-10-02 |
| 56621 | use after free in InlineBox::dirtyLineBoxes() | - | 2016-10-02 |
| 56616 | Bad cast in 3d rendering in RenderObject::getTransformFromContainer | - | 2016-10-02 |
| 56514 | Click to Play is vulnerable to UI redressing | - | 2016-10-02 |
| 56653 | Named popup windows bug | - | 2016-10-02 |
| 56468 | MAJOR Password Security problem | - | 2016-10-02 |
| 56451 | cross_fuzz: Deleted elements lingering in Document::m_elementsById | - | 2016-10-02 |
| 56449 | Crash in Pickle::ReadInt in net::HttpResponseInfo::InitFromPickle | - | 2016-10-02 |
| 56722 | Browser crash on closing incognito @ ToolbarView::Layout() | - | 2016-10-02 |
| 56474 | User after free in table destroy | - | 2016-10-02 |
| 56252 | Factory::LookupSymbol+0x3e - Crash | - | 2016-10-02 |
| 56237 | Browser crash in incognito mode with trying to close a large db. | - | 2016-10-02 |
| 56206 | Use after free in CounterNode | - | 2016-10-02 |
| 56144 | Memory corruption in adding text child to table column | - | 2016-10-02 |
| 56127 | Ă©ÂÂĂŁÂÂĂŁÂÂŸĂŁÂ | - | 2016-10-02 |
| 56394 | Bad cast in ApplyStyleCommand::applyInlineStyleToPushDown | - | 2016-10-02 |
| 55957 | Merge webkit bug 45869: Use after free in ImageLayerChromium | - | 2016-10-02 |
| 55901 | Merge Webkit Bug 45896 :CSS: Fix crash in getTimingFunctionValue() | - | 2016-10-02 |
| 55751 | vulnerability Google chrome clickjacking | - | 2016-10-02 |
| 55745 | MSVR-10-0105: Cross origin bypass using canvas and video | - | 2016-10-02 |
| 55675 | Stale owner element called in frame's disconnectOwnerElement | - | 2016-10-02 |
| 55607 | Flash intercepts key events when not in focus | - | 2016-10-02 |
| 55350 | Chrome cross window & cross domain object access | $1,000 | 2016-10-02 |
| 55831 | Segmentation fault at WebCore::ImageLoader::updateFromElement due to malformed HTML | $1,000 | 2016-10-02 |
| 55330 | Treebuilder parsing in out of context when encountering special tags like </kbd> | - | 2016-10-02 |
| 55346 | Load Timer fired on deleted HTMLMediaElement | $1,000 | 2016-10-02 |
| 230907 | Heap-use-after-free in WebCore::RenderBox::exclusionShapeOutsideInfo | - | 2016-10-02 |
| 230730 | ASSERTION FAILED: m_insertionPoint->inDocument(), Heap-use-after-free in WebCore::ElementRuleCollector::collectMatchingRulesForList | - | 2016-10-02 |
| 230729 | Heap-use-after-free in non-virtual thunk to WebKit::WebPluginContainerImpl::clearScriptObjects | - | 2016-10-02 |
| 230915 | Security: strongSwan ECDSA signature vulnerability | - | 2016-10-02 |
| 230726 | ASSERTION FAILED: i < m_length, UNKNOWN in WebCore::InlineTextBox::isLineBreak | - | 2016-10-02 |
| 230725 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
| 230720 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 230176 | Security: Type confusion vulnerability in V8Clipboard::setDragImageMethodCustom | $1,500 | 2016-10-02 |
| 230117 | Heap-use-after-free in webkit_media::WebMediaPlayerImpl::paint | $1,000 | 2016-10-02 |
| 229504 | Interstitials allow bypass of extension permissions | - | 2016-10-02 |
| 230728 | Heap-use-after-free in WebCore::WidgetHierarchyUpdatesSuspensionScope::moveWidgets | - | 2016-10-02 |
| 229020 | ASSERTION FAILED: i < size(), UNKNOWN in WebCore::RenderLayer::hitTestList | - | 2016-10-02 |
| 229019 | Input pointer corruption in xmlParseTryOrFinish | - | 2016-10-02 |
| 227390 | ExtensionFunctionRegistry: missing check for iter != factories_.end() | - | 2016-10-02 |
| 227350 | Security: UAF in ppapi::ScopedPPResource::CallRelease | $1,000 | 2016-10-02 |
| 227197 | Security: infoleak in Buffer::Set in O3D | - | 2016-10-02 |
| 229402 | Another popunder scheme | - | 2016-10-02 |
| 227158 | Security: domain authorization issue in O3D | - | 2016-10-02 |
| 227157 | Global-buffer-overflow in WebCore::Font::expansionOpportunityCount | - | 2016-10-02 |
| 227181 | Security: UAF in O3D | - | 2016-10-02 |
| 226937 | Security: Postpwnium: Full exploit chain for ChromeOS | $31,336 | 2016-10-02 |
| 226928 | Null-pointer exec from SkDeferredCanvas::setDeferredDrawing | - | 2016-10-02 |
| 226696 | Security: use-after-free removing a frame from its parent in a beforeload event of an OBJECT element | $2,000 | 2016-10-02 |
| 226659 | Harden WTF::Vector::operator[] | - | 2016-10-02 |
| 226091 | ASSERTION FAILED: !node || node->isShadowRoot(), UNKNOWN in WebCore::EventRetargeter::eventTargetRespectingTargetRules | - | 2016-10-02 |
| 226090 | Heap-use-after-free in WebCore::IDBDatabase::onComplete | - | 2016-10-02 |
| 227040 | Heap-use-after-free in moveOverlapping | - | 2016-10-02 |
| 226068 | Security: HSTS will not work if Strict-Transport-Security header and Public-Key-Pins header are present in this order | - | 2016-10-02 |
| 226012 | clicking links using generated mouse events bypasses the popup blocker | - | 2016-10-02 |
| 225979 | Heap-use-after-free in WebCore::RenderTextControl::visiblePositionForIndex | - | 2016-10-02 |
| 225969 | Consider locking screen when turning screen off rather than when suspending | - | 2016-10-02 |
| 225798 | Swiftshader images do not use aslr | - | 2016-10-02 |
| 225565 | Security: strongswan must not write files into /mnt/stateful_partition directly | - | 2016-10-02 |
| 225546 | Security: u-a-f in shared worker process in Allow{IndexedDB,FileSystem}MainThreadBridge | $1,337 | 2016-10-02 |
| 225496 | chrome_5eb80000!views::FocusManager::AdvanceFocus Crash | - | 2016-10-02 |
| 225417 | Heap-use-after-free in TabStripGtk::DestroyDraggedTab | - | 2016-10-02 |
| 225403 | ASSERTION FAILED: ownerElement->contentFrame() == frame || !ownerElement->contentFrame(), Heap-use-after-free in WebCore::Node::isDescendantOf | - | 2016-10-02 |
| 225226 | It's possible to bypass the permission restrictions for chrome.tabs.captureVisibleTab | - | 2016-10-02 |
| 224920 | ASSERTION FAILED: !object || object->isBox(), UNKNOWN in WebCore::RenderBlock::layoutBlockChildren | - | 2016-10-02 |
| 224734 | Incorporate standalone utilities into futility | - | 2016-10-02 |
| 223962 | Heap-use-after-free in WebCore::Reverb::latencyFrames | $500 | 2016-10-02 |
| 224624 | Security: XSS in 1993 chrome | - | 2016-10-02 |
| 223772 | Attempting free when chrome.fontSettings.getFontList is called twice in background script | - | 2016-10-02 |
| 223444 | Kernel stack info leak via the tkill and the tgkill syscalls | $500 | 2016-10-02 |
| 223376 | ASSERTION FAILED: !node || node->isHTMLElement(), UNKNOWN in WebCore::toHTMLElement | - | 2016-10-02 |
| 223835 | ASSERTION FAILED: candidate.isCandidate(), Heap-use-after-free in WebKit::ChromeClientImpl::didAssociateFormControls | - | 2016-10-02 |
| 223482 | Heap-use-after-free in WebCore::HTMLTreeBuilder::callTheAdoptionAgency | - | 2016-10-02 |
| 55257 | Memory corruption in accessing floatptr of a textarea | $1,000 | 2016-10-02 |
| 55215 | Memory corruption with styled font-face | - | 2016-10-02 |
| 55179 | Memory corruption with reparentchildren in new treebuilder | - | 2016-10-02 |
| 55119 | SpdyFramer buffer resizing bug | - | 2016-10-02 |
| 55114 | Bad cast with svg:g element | $500 | 2016-10-02 |
| 54794 | HTML5 Workers run outside of the sandbox | - | 2016-10-02 |
| 54697 | Extension APIs should include password encryption | - | 2016-10-02 |
| 54691 | segmentation fault in bundled pdf plugin | $1,000 | 2016-10-02 |
| 54661 | SSL connexion error after update to CHROME v6.0.472.53 | - | 2016-10-02 |
| 54653 | Memory corruption with creating lines on renderblocks. | - | 2016-10-02 |
| 54636 | selectedStylesheetSet memory corruption | - | 2016-10-02 |
| 54539 | OOB read in rendering text fragment | - | 2016-10-02 |
| 54880 | Crash at gfx::CGImageToSkBitmap | - | 2016-10-02 |
| 54532 | Issue with incorrect attribute, events handling in SVG and polyline | - | 2016-10-02 |
| 54500 | Renderer crash on very big animated gif image @ WebCore::RGBA32Buffer::setRGBA(unsigned int *,unsigned int,unsigned int,unsigned int,unsigned int) | $500 | 2016-10-02 |
| 54312 | My Other MacBook Was Stolen/Robbed from My HOme and the Hacker is taking Pride in Torturing me | - | 2016-10-02 |
| 54268 | MacOSX WebGL Uninitialized Canvas Information Leak | - | 2016-10-02 |
| 54262 | Possible Location Bar & SSL Spoofing | $1,000 | 2016-10-02 |
| 54132 | Security: Insecure library loading in Google Chrome for Linux | - | 2016-10-02 |
| 54054 | Device3DInitialize Uninitialized Object Vulnerability | - | 2016-10-02 |
| 54313 | My Other MacBook Was Stolen/Robbed from My HOme and the Hacker is taking Pride in Torturing me | - | 2016-10-02 |
| 54006 | Security: Extension history permission does not generate a warning | - | 2016-10-02 |
| 53985 | Crash in chrome_browser_net_websocket_experiment::WebSocketExperimentRunner::DoLoop | - | 2016-10-02 |
| 53949 | HTTPS -> HTTP redirected CSS and JS do not trigger mixed content | - | 2016-10-02 |
| 53930 | Memory corruption on Linux when render Khmer script page | - | 2016-10-02 |
| 53912 | Crash on shutdown in BrowsingInstance::GetSiteInstanceMap | - | 2016-10-02 |
| 53892 | A Cryptographically secure random number generator implementation for V8 | - | 2016-10-02 |
| 53836 | wss:// does not validate SSL certs | - | 2016-10-02 |
| 53747 | Use-after-free of renderer when recalcStyle() is called during layout or painting. | - | 2016-10-02 |
| 53994 | save | - | 2016-10-02 |
| 53645 | Function names are exposed to iframes from non-same origin using console API | - | 2016-10-02 |
| 53640 | Merge Webkit Bug 41523 to 472 | - | 2016-10-02 |
| 53394 | Geolocation use after free | $500 | 2016-10-02 |
| 53361 | Browser crash in improper destruction of select file dialog (mac) | $500 | 2016-10-02 |
| 53230 | crash on google.at ajax search | - | 2016-10-02 |
| 53176 | BlockedPopupContainer::GetBlockedContents ReadAV@NULL (882a25e76e991e980ffce6adda7cfcc5) | - | 2016-10-02 |
| 53002 | pop blocker bypass | - | 2016-10-02 |
| 53142 | EXTERNAL-REPORT: Another Windows kernel CFF font parsing bug | - | 2016-10-02 |
| 53039 | Geolocation use after free | - | 2016-10-02 |
| 53017 | MEMORY CORRUPT | - | 2016-10-02 |
| 53008 | Security: can't update flash from about:plugins in chromium | - | 2016-10-02 |
| 53068 | download without user permission | - | 2016-10-02 |
| 53001 | Security: ability to read cross domain image data using toDataURL and getImageData via createPattern | $500 | 2016-10-02 |
| 52980 | GOOGLE CHOME MEMORY CORRUPT | - | 2016-10-02 |
| 52961 | Security: user.qzone.qq.com | - | 2016-10-02 |
| 52958 | Trojan can sync with my sync data ??? | - | 2016-10-02 |
| 53116 | Security: Chrome can't be downloaded securely. | - | 2016-10-02 |
| 52870 | error | - | 2016-10-02 |
| 52782 | close window with javascript | - | 2016-10-02 |
| 52682 | Sandbox IPC out-of-bounds write in CrossCallParamsEx::CreateFromBuffer | $1,000 | 2016-10-02 |
| 52587 | cross_fuzz: CSSRule::parentStyleSheet use after free | - | 2016-10-02 |
| 52581 | HTML5 TreeBuilder ASSERTs on <a><svg><tr><input></a> | - | 2016-10-02 |
| 52456 | Chrome attempts to connect to HTTP://nikkomsgchannel when focus moves to a password field on any page | - | 2016-10-02 |
| 52443 | Google Chrome Focus Handling Use-after-free Vulnerability | - | 2016-10-02 |
| 52420 | MAJOR CHROME SECURITY BUG : Chrome exposes the secrete question and answer for google's gmail password retrial mechanism | - | 2016-10-02 |
| 51739 | Numerous Integer wraps and errant pointers within WebSockets parser | - | 2016-10-02 |
| 52413 | Major Chrome security BUG : Confidential User data accessiblity Security Bug :[ Test case of Gmail account registration included] | - | 2016-10-02 |
| 52204 | Regression: Incorrect destruction of "empty anonymous block" in renderblock remove child. | $1,000 | 2016-10-02 |
| 52067 | ExtensionsService::IsGalleryDownloadUrl ignores scheme | - | 2016-10-02 |
| 51919 | use after free in console.profile calls. | $500 | 2016-10-02 |
| 51865 | Chrome Search Box: Index error | - | 2016-10-02 |
| 51846 | Null deref when socket stream is closed during hostname resolution | - | 2016-10-02 |
| 52364 | Valgrind error in CGPDFDrawingContextDraw() on mac ui tests | - | 2016-10-02 |
| 51727 | autocomplete entries submitted by javascript should not be stored in db (similar to autofill bug 48225) | - | 2016-10-02 |
| 51709 | Fatal assertion failure when getting gdk custom cursor on safari books | - | 2016-10-02 |
| 51690 | Security of accounts | - | 2016-10-02 |
| 51680 | Omnibox url spoofing on pending events in page unload | $500 | 2016-10-02 |
| 51670 | Security: WebKit: WebCore::GeolocationService::positionChanged use after free | $1,000 | 2016-10-02 |
| 51658 | Add .xbap to dangerous extensions list | - | 2016-10-02 |
| 238842 | Crash in WebCore::Canvas2DLayerBridge::prepareForDraw() | - | 2016-10-02 |
| 238837 | Limit the depth of function calls in GLSL | - | 2016-10-02 |
| 239013 | Two logins may happen at the same time if network goes offline during login | - | 2016-10-02 |
| 238041 | document.cookie denial-of-service | - | 2016-10-02 |
| 237800 | use-after-free on WebCore::MajorGCWrapperVisitor::VisitPersistentHandle | - | 2016-10-02 |
| 237562 | Security: update curl to resolve CVE-2013-1944 and CVE-2013-2174 | - | 2016-10-02 |
| 237526 | ~URLRequestFtpJob: NULL deref of request_ | - | 2016-10-02 |
| 237429 | Heap-use-after-free in WebCore::EventTarget::dispatchEvent | - | 2016-10-02 |
| 237611 | Security: Screen capture via WebGL texture | $500 | 2016-10-02 |
| 237104 | Security: CSP doesn't get applied to inline event handlers that were executed once before. | - | 2016-10-02 |
| 237022 | Cross-origin named subframe access leaks cross-origin subframes of the same name | $1,500 | 2016-10-02 |
| 236845 | ASSERTION FAILED: node->treeScope() == m_oldScope, Heap-use-after-free in WebCore::Node::~Node | - | 2016-10-02 |
| 237263 | Security: Possible for renderer process to read arbitrary files by tricking session restore | - | 2016-10-02 |
| 236846 | Global-buffer-overflow in WebRtcIsac_UpdateBwEstimate | - | 2016-10-02 |
| 236556 | use-after-free on WebCore::FormController::createSavedFormStateMap | - | 2016-10-02 |
| 236631 | GpuProcessHost: check channel_requests_.empty() | - | 2016-10-02 |
| 236147 | Heap-use-after-free in printing::PrepareFrameAndViewForPrint::PrepareFrameAndViewForPrint | - | 2016-10-02 |
| 236269 | ASSERTION FAILED: !m_deletionHasBegun, UNKNOWN in WebCore::DeviceOrientationEvent::~DeviceOrientationEvent | - | 2016-10-02 |
| 236630 | Security: chronos-writable /var/run/chrome on Chrome OS subject to symlink tricks and other mal manipulations | - | 2016-10-02 |
| 236245 | Heap-use-after-free in WebCore::FrameView::updateWidget | - | 2016-10-02 |
| 235638 | ASSERTION FAILED: m_table, Heap-use-after-free in WTF::HashTable<WebCore::SVGElement const*, WTF::KeyValuePair<WebCore::SVGElement const*, WebCore::SV | $1,000 | 2016-10-02 |
| 235733 | Heap-use-after-free in WebCore::AudioNodeOutput::~AudioNodeOutput | $1,000 | 2016-10-02 |
| 236139 | ASSERTION FAILED: node->treeScope() == m_oldScope, Heap-use-after-free in void WebCore::Private::addChildNodesToDeletionQueue<WebCore::Node, WebCore::ContainerNode> | $1,000 | 2016-10-02 |
| 235311 | [LangFuzz] Crash on heap with invalid read on dangerous (possibly uninitialized) address (64 bit) | $500 | 2016-10-02 |
| 235732 | Heap-buffer-overflow in SkA1_Blitter::blitH | - | 2016-10-02 |
| 235271 | Security: Isolated Filesystem API does not fully check for references to parent in pathname | - | 2016-10-02 |
| 234689 | Possible XSS vector in New Tab Page | - | 2016-10-02 |
| 234809 | URL spoof or renderer kill when committing prerendered/instant page with a pending entry | - | 2016-10-02 |
| 234937 | Security: the GPU sandbox is not enabled in guest mode on Chrome OS. | - | 2016-10-02 |
| 235161 | HostResolver can be caused to pass empty DNS components to DnsQuery | - | 2016-10-02 |
| 234635 | UNKNOWN in cssyyparse | - | 2016-10-02 |
| 234724 | Chrome Extension API bindings: Definition should not depend on any user/extension mutable prototype objects | - | 2016-10-02 |
| 234491 | Heap-use-after-free in content::NavigationControllerImpl::RendererDidNavigateToExistingPage | - | 2016-10-02 |
| 233261 | Heap-use-after-free in content::NotificationServiceImpl::Notify | - | 2016-10-02 |
| 233848 | ASSERTION FAILED: run.charactersLength() >= run.length(), Heap-buffer-overflow in WebCore::Font::characterRangeCodePath | $500 | 2016-10-02 |
| 234190 | Heap-use-after-free in SkAlphaRuns::add | - | 2016-10-02 |
| 234198 | ASSERTION FAILED: value->isValueList(), UNKNOWN in WebCore::createGridPosition | - | 2016-10-02 |
| 232865 | Potential use after free in ApplyStyleCommand::splitAncestorsWithUnicodeBidi | - | 2016-10-02 |
| 232743 | use-after-free on WebCore::DOMWrapperMap<void>::removeAndDispose | - | 2016-10-02 |
| 232633 | use-after-free on net::SSLClientSocketNSS::Core::OnSendComplete | - | 2016-10-02 |
| 232763 | use-after-free on WebCore::JPEGImageReader::decode | - | 2016-10-02 |
| 232475 | use-after-free on AutofillPopupControllerImpl::Hide | - | 2016-10-02 |
| 232393 | Heap-buffer-overflow in WebCore::CSSPrimitiveValue::cleanup | - | 2016-10-02 |
| 232389 | ASSERTION FAILED: !object || object->isRenderInline(), UNKNOWN in WebCore::RenderTextTrackCue::initializeLayoutParameters | - | 2016-10-02 |
| 232064 | Heap-use-after-free in WebCore::MediaStreamTrack::stop | - | 2016-10-02 |
| 232625 | use-after-free on InstantController::ReloadOverlayIfStale | - | 2016-10-02 |
| 232570 | use-after-free on content::RendererAccessibilityFocusOnly::HandleFocusedNodeChanged | - | 2016-10-02 |
| 232532 | use-after-free on IPC::ChannelProxy::Context::OnChannelError | - | 2016-10-02 |
| 232519 | use-after-free on ProfileKeyedServiceFactory::ProfileDestroyed | - | 2016-10-02 |
| 231688 | Security: Chrome's IntentHandler relies on weak authentication | - | 2016-10-02 |
| 231128 | UNKNOWN in cricket::VideoFrame::Validate | - | 2016-10-02 |
| 231127 | Heap-buffer-overflow inWebCore::(anonymous namespace)::fixUnparsedProperties<unsigned char>(unsigned char const*, WebCore::CSSRuleSourceData*) | - | 2016-10-02 |
| 51525 | Found a bug in the playback of media files via Google Chrome | - | 2016-10-02 |
| 51511 | Crash in accessibility code on Windows when opening the wrench menu. | - | 2016-10-02 |
| 51653 | Memory corruption in Counter Nodes. | $500 | 2016-10-02 |
| 51602 | Investigate rte_fuzz crashes | - | 2016-10-02 |
| 51630 | Memory corruption in WebSocketChannel::skipBuffer() - underflow in buffer size | $1,337 | 2016-10-02 |
| 51654 | Memory corruption with moving ruby text nodes to runs without ruby bases. | $1,000 | 2016-10-02 |
| 51146 | Plain-text information leak of https://user:password due to autosuggest | - | 2016-10-02 |
| 51070 | Another Windows kernel bug in the CFF font parser | $1,337 | 2016-10-02 |
| 51240 | Type confusion bug between LargeObjectChunk header and Page header | - | 2016-10-02 |
| 51464 | Chromium use ActiveX Flash (not the NPAPI one) with potential WinINET cookie leak | - | 2016-10-02 |
| 51476 | Memory corruption in tree builder | - | 2016-10-02 |
| 51252 | Use after free with nested use elements | $500 | 2016-10-02 |
| 50920 | breakdown while alt+z clicked in win7 | - | 2016-10-02 |
| 50647 | Page with tables crashes the browser | - | 2016-10-02 |
| 50553 | Crash when closing chrome - BalloonViewImpl::DelayedClose | $1,337 | 2016-10-02 |
| 50530 | Google Relay Service for the Deaf and Hard of Hearings. | - | 2016-10-02 |
| 50428 | Browser crash @ TabContents::ExpireInfoBars | - | 2016-10-02 |
| 50839 | Security: WebKit 43295 - cross_fuzz notification requestPermission memory corruption | - | 2016-10-02 |
| 50741 | ChromeFrame allows navigation to "gcf:" urls | - | 2016-10-02 |
| 50712 | Use after free with SVG use referencing svg style element | $1,000 | 2016-10-02 |
| 50377 | User gesture leaks from prompt (was: infinite prompts) | - | 2016-10-02 |
| 50253 | Elide long omnibox entries on Mac. | - | 2016-10-02 |
| 50250 | Use after free in document.close() | $500 | 2016-10-02 |
| 50110 | Downloading a file adds extension to the extension already in filename | - | 2016-10-02 |
| 50409 | Zoom bug | - | 2016-10-02 |
| 50383 | Glibc bug in getaddrinfo() may be exposed | - | 2016-10-02 |
| 50315 | Code prevents the closing of tab/browser window. | - | 2016-10-02 |
| 49932 | Failure on page load | - | 2016-10-02 |
| 49747 | GTK message dialogs do not properly wrap overly long words or elide many short lines in js modal dialog | - | 2016-10-02 |
| 49745 | Regression: Pop up blocker not working as expected | - | 2016-10-02 |
| 49729 | Use after free in scroll bar layout | - | 2016-10-02 |
| 49628 | Memory corruption with invalid text node cast for edit commands | $500 | 2016-10-02 |
| 49964 | Security: window.history.replaceState fails to enforce domain security | $1,000 | 2016-10-02 |
| 49910 | Compatibility error with power strip | - | 2016-10-02 |
| 50029 | Security: showModalDialog() bypasses the usual anti-annoyance checks | - | 2016-10-02 |
| 49982 | Proxy Config Fail - Security fail | - | 2016-10-02 |
| 49332 | Autofill can hang the entire browser (DOS) because of stuck on IO Thread processing infinite data | - | 2016-10-02 |
| 49318 | Merge webkit bug https://bugs.webkit.org/show_bug.cgi?id=39143 | - | 2016-10-02 |
| 49317 | Merge webkit bug https://bugs.webkit.org/show_bug.cgi?id=40407 | - | 2016-10-02 |
| 49222 | StringImpl::replace integer overflow | - | 2016-10-02 |
| 49215 | Signed/Unsigned Comparison issue in MemoryAllocator::AllocateRawMemory | - | 2016-10-02 |
| 49596 | Security issue in SVGUseElement::buildShadowTree | $500 | 2016-10-02 |
| 49377 | X509Certificate::Cache usage pattern may result in use after free | - | 2016-10-02 |
| 49346 | Sync allows an attacker who compromises Google credentials to push extensions to a user's browser | - | 2016-10-02 |
| 49166 | kdsfgmkladsfjljdf | - | 2016-10-02 |
| 49188 | ChromeFrame window.open("javascript:window.open('http://example.com/');"); => NULL ptr crash | - | 2016-10-02 |
| 48857 | Render crash in FormManager::FindCachedFormElement() | - | 2016-10-02 |
| 49177 | Extension updates don't identify privilege increases when scheme changes | - | 2016-10-02 |
| 49172 | AutoFill causes browser crash when saving large profiles | - | 2016-10-02 |
| 49047 | Open a share-point site will cause the browser to crash | - | 2016-10-02 |
| 48499 | Should autofill credit card infomation over an https page only | - | 2016-10-02 |
| 48330 | Security: WebSocket: Integer underflow in header length calculation triggers browser DoS | - | 2016-10-02 |
| 48288 | Crash site | - | 2016-10-02 |
| 48597 | Incorrect eliding (windows), truncation(linux) for hostname in security information dialog | - | 2016-10-02 |
| 48733 | Crash in third_party xdg_mime library when unable to handle long file paths | $1,337 | 2016-10-02 |
| 48440 | Localhost XSS | - | 2016-10-02 |
| 48282 | LegacyHTMLTreeBuilder fires DOM mutation events | - | 2016-10-02 |
| 48233 | Steal any autofill field using javascript while user is hovering over one of the selection. | - | 2016-10-02 |
| 247038 | Heap-use-after-free in WebCore::V8HTMLFormControlsCollection::indexedPropertyGetter | - | 2016-10-02 |
| 246724 | Security: Ensure that all request types use pinning | - | 2016-10-02 |
| 48284 | <use> on <font-face> causes crashes, if SVGUseElement gets detached | $500 | 2016-10-02 |
| 246635 | Heap-buffer-overflow in WebCore::HTMLMapElement::imageElement | - | 2016-10-02 |
| 246240 | ResourceHostMsg_DataReceived_ACK: heap corruption | - | 2016-10-02 |
| 246205 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
| 246203 | Heap-use-after-free in WebCore::V8GCController::opaqueRootForGC | - | 2016-10-02 |
| 48283 | EXTERNAL-REPORT: Windows kernel crash on invalid font | $1,337 | 2016-10-02 |
| 246701 | UNKNOWN in WebCore::DownSampler::process | - | 2016-10-02 |
| 245727 | Heap-use-after-free in WebCore::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
| 245153 | PDF: OOB read in JPEG2000 image handling | - | 2016-10-02 |
| 245941 | Heap-use-after-free in base::internal::CallbackBase::Reset | - | 2016-10-02 |
| 245368 | Infobar Google Update plugin by default | - | 2016-10-02 |
| 244415 | SpeechRecognizerImpl UaF | - | 2016-10-02 |
| 244260 | Security: TLS Truncation attack on HTTP headers, including cookie flags | $3,133 | 2016-10-02 |
| 244056 | Heap-use-after-free in WebCore::RenderTextFragment::willBeDestroyed | - | 2016-10-02 |
| 244036 | ASSERTION FAILED: node->parentNode(), Heap-use-after-free in WebCore::RenderBox::exclusionShapeOutsideInfo | $1,000 | 2016-10-02 |
| 244021 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImages | - | 2016-10-02 |
| 243991 | Heap-use-after-free in WebCore::InputType::stepUpFromRenderer | $1,000 | 2016-10-02 |
| 243881 | ASSERTION FAILED: actualInfo->derefObjectFunction == V8HTMLSpanElement::info.derefObjectFunction, UNKNOWN in WebCore::wrap | - | 2016-10-02 |
| 245121 | Security: Cloud-printing Robot-Account storage in Local State lacks integrity, permits redirection to evil printers | - | 2016-10-02 |
| 244746 | UrlRequestContext can be deleted while a live SocketStream has a pointer to it (vtable UAF) | $3,133 | 2016-10-02 |
| 244080 | UNKNOWN in v8::internal::Object::GetProperty | - | 2016-10-02 |
| 243339 | Security: CheckDuplicateHandle (BreakDebugger) browser crash with (Web) Workers and WebSQL | $2,000 | 2016-10-02 |
| 242931 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
| 242924 | [LangFuzz] Crash at v8::internal::HeapObject::Size() on 64 bit with invalid read | $1,000 | 2016-10-02 |
| 242819 | Security: Registering on Gerrit with Any Email [Auth Problem] | - | 2016-10-02 |
| 242786 | Heap-double-free in av_destruct_packet | - | 2016-10-02 |
| 243512 | base/time_posix executes signed overflow with 64-bit time_t | - | 2016-10-02 |
| 243875 | ResourceHostMsg_RequestResource: validate request_data.priority enum | - | 2016-10-02 |
| 243818 | Heap-use-after-free in WebCore::StyledElement::ensureMutableInlineStyle | $1,000 | 2016-10-02 |
| 243045 | ASSERTION FAILED: !m_deletionHasBegun, Heap-use-after-free in WebCore::GenericEventQueue::enqueueEvent | - | 2016-10-02 |
| 242322 | Escalate access to browser internals | $500 | 2016-10-02 |
| 242224 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::~BaseMultipleFieldsDateAndTimeInputType | $1,000 | 2016-10-02 |
| 242114 | Heap-use-after-free in WebCore::Range::compareBoundaryPoints | - | 2016-10-02 |
| 242762 | Security: Use-after-free in net::SocketStream::Finish | $3,133 | 2016-10-02 |
| 242702 | NSS is unable to open /dev/urandom on OS X, resulting in insufficient entropy for renderers | - | 2016-10-02 |
| 242502 | UNKNOWN in v8::internal::TypeFeedbackOracle::CanRetainOtherContext | - | 2016-10-02 |
| 240984 | Security: Merge http://trac.webkit.org/changeset/150072 | - | 2016-10-02 |
| 240961 | Zero-sized textures must be considered incomplete | - | 2016-10-02 |
| 240706 | Security: perf_swevent_init does not check negative argument | - | 2016-10-02 |
| 242023 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
| 241607 | `git cl upload` can add patches to other peoples' issues | - | 2016-10-02 |
| 241139 | Heap-use-after-free in webkit_glue::WebURLLoaderImpl::Context::OnReceivedResponse | $1,000 | 2016-10-02 |
| 240124 | Heap-use-after-free in WebCore::ImageInputType::attach | $1,000 | 2016-10-02 |
| 240056 | UNKNOWN in int v8::internal::FlexibleBodyVisitor<v8::internal::NewSpaceScavenger, v8::internal::JSObject::BodyD | - | 2016-10-02 |
| 240139 | Security: gerrit.chromium.org is running an outdated version of OpenId4Java | - | 2016-10-02 |
| 240057 | Heap-use-after-free in WebCore::accumulateDocumentEventTargetRects | - | 2016-10-02 |
| 240449 | Crash in base::DeleteHelper<safe_browsing::DownloadProtectionService::CheckClientDownloadRequest>::DoDelete(void const *) | - | 2016-10-02 |
| 240490 | Security: Set HSTS preloads for translate.google[apis].com | - | 2016-10-02 |
| 240055 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
| 239699 | Instant Extended on mobile platforms allows sboxchip spoofing | - | 2016-10-02 |
| 239580 | Heap-use-after-free in net::SniffMimeType | - | 2016-10-02 |
| 240054 | ASSERTION FAILED: m_requestCount == 0, Heap-use-after-free in WebCore::CachedResourceLoader::decrementRequestCount | - | 2016-10-02 |
| 240032 | Security: chrome_70ee0000!v8::internal::ScavengingVisitor<1,1>::EvacuateShortcutCandidate crash | $500 | 2016-10-02 |
| 239897 | Tab crashes when changing <audio> element source when used with Web Audio API | $500 | 2016-10-02 |
| 239411 | ANGLE: check negative vector/matrix/array index | - | 2016-10-02 |
| 239134 | PDF: bad free in JBIG2 PDF decoder | - | 2016-10-02 |
| 48115 | REGRESSION: Memory corruption in open source JPEG decoder (r61619) | $500 | 2016-10-02 |
| 48167 | Security: CRITICAL EXECUTABLE MISSING FUNCTION FLAW | - | 2016-10-02 |
| 48043 | dadasdadasdas | - | 2016-10-02 |
| 48225 | Autofill profile (address, perfsonal info) spam without any need of user interaction | - | 2016-10-02 |
| 48093 | Chromoting enabled by default in Chromium | - | 2016-10-02 |
| 47105 | Renderer crash for a multipart page | - | 2016-10-02 |
| 47866 | Memory corruption with crash in RenderObject::containingBlock() | $500 | 2016-10-02 |
| 47253 | ref_fuzz crash 2 | - | 2016-10-02 |
| 47252 | ref_fuzz crash | - | 2016-10-02 |
| 47160 | possblie access file: chrome: | - | 2016-10-02 |
| 47395 | Security: Modification over GUI | - | 2016-10-02 |
| 47086 | Memory corruption with DOM mutation on onchange event firing for select object | - | 2016-10-02 |
| 47056 | Browser crash after AppModalDialogQueue::ShowNextDialog | - | 2016-10-02 |
| 47915 | ZDI-CAN-806: Apple Safari's Webkit Runin Use-after-free Vulnerability | - | 2016-10-02 |
| 47938 | error tags html | - | 2016-10-02 |
| 47515 | Security: Reproducable and Controllable Memory Leak in about:memory page | - | 2016-10-02 |
| 46750 | Browser crash in WebSocket creation | - | 2016-10-02 |
| 46575 | DoS by opening unlimited number of print dialogs | - | 2016-10-02 |
| 46516 | Need to sync extension permissions | - | 2016-10-02 |
| 46509 | error al descargar | - | 2016-10-02 |
| 46452 | ::-webkit-scrollbar causes "Aw Snap" when combined with certain JavaScripts | - | 2016-10-02 |
| 46401 | Google Chrome does not prompt for user permission before using HTML5's offline features | - | 2016-10-02 |
| 46360 | Memory corruption in :first-letter rendering | $500 | 2016-10-02 |
| 46792 | Security Vulnerability in Chrome 5.0.375.70 | - | 2016-10-02 |
| 46788 | help me! | - | 2016-10-02 |
| 46008 | Wrapping shared memory allocation in X backing store | - | 2016-10-02 |
| 46018 | Crash - BalloonViewImpl::DelayedClose | - | 2016-10-02 |
| 45923 | Browser not checking site's domain on password type inputs | - | 2016-10-02 |
| 45876 | Web pages should NOT be able to load resources if there are NO content scripts from that extension on the page | - | 2016-10-02 |
| 45799 | possible privilege escalation via named pipes (NaCL) | - | 2016-10-02 |
| 45683 | jjjjj | - | 2016-10-02 |
| 46126 | crash with processing invalid x509-user-cert responses. | $500 | 2016-10-02 |
| 45983 | Segmentation fault in WebCore::RenderLayer::paintList when a malformed PNG image is viewed | $1,000 | 2016-10-02 |
| 45614 | ZDI-CAN-782: Apple Webkit SVG First-Letter Style Remote Code Execution Vulnerability | - | 2016-10-02 |
| 45615 | ZDI-CAN-785: Apple Webkit SVG Floating Text Element Remote Code Execution Vulnerability | - | 2016-10-02 |
| 45524 | crash | - | 2016-10-02 |
| 45506 | User ID Issue | - | 2016-10-02 |
| 45494 | Function names are exposed to iframes from non-same origin using console API | - | 2016-10-02 |
| 45412 | Trojan Horse exploit_c.FWR | - | 2016-10-02 |
| 45267 | ViewHostMsg_UpdateVideo memory corruption | - | 2016-10-02 |
| 45164 | Crash with invalid images. | - | 2016-10-02 |
| 45659 | Stale pointer in SVGResourceFilter | - | 2016-10-02 |
| 45609 | ZDI-CAN-784: Apple Webkit Rendering Counter Remote Code Execution Vulnerability | - | 2016-10-02 |
| 44955 | Need to merge WebCore::toAlphabetic() crash to 375 branch. | - | 2016-10-02 |
| 44868 | Geolocation events fire after document deletion | - | 2016-10-02 |
| 44835 | 1337 on goggle search | - | 2016-10-02 |
| 44796 | Please disallow "javascript:" URLs in the address bar | - | 2016-10-02 |
| 45033 | Issue with frames[].location | - | 2016-10-02 |
| 44742 | a bug of the scrollbar in iframe | - | 2016-10-02 |
| 44740 | Need to merge fix for WebKit font issue to 375 branch | - | 2016-10-02 |
| 44658 | Security: Insecure behavior in /tmp by Keystone on Mac OS X | $500 | 2016-10-02 |
| 44759 | sad tab with little script | - | 2016-10-02 |
| 44556 | Security: WebKit: WebCore::RenderInline::destroy ExecAV@Arbitrary (b1c9c3c46df454874e36c9f86b2418fa) | - | 2016-10-02 |
| 44424 | security:chrome_1c30000!WebCore::InlineBox::paint+0x70 | $500 | 2016-10-02 |
| 44193 | Security: Chrome saves plaintext passwords even when "save passwords" is disabled | - | 2016-10-02 |
| 43967 | REGRESSION: Currently loading subresource displayed in omnibox | - | 2016-10-02 |
| 43902 | innerHTML decompilation issues in textarea | - | 2016-10-02 |
| 43846 | Null deref during image drag, crash in drag selection controller. | - | 2016-10-02 |
| 43813 | chrome_1c30000!SkAlphaRuns::Break+0x13 - Memory Corruption | $500 | 2016-10-02 |
| 44500 | Invalid read handling malformed SVG <use> element | - | 2016-10-02 |
| 43487 | ZDI-CAN-765: CSS Charset Text Transformation Vulnerability | - | 2016-10-02 |
| 43446 | Kapersky Vulnerablity | - | 2016-10-02 |
| 43315 | [MD audit] Stale pointer error when normalizing DOM nodes | - | 2016-10-02 |
| 43307 | [MD audit] Possible memory corruption with bad bitmap shared memory object in clipboard IPC | - | 2016-10-02 |
| 43304 | [MD audit] Linux sandbox escape | - | 2016-10-02 |
| 42989 | Mac sandbox allows calls to stat() on arbitrary paths. | - | 2016-10-02 |
| 43488 | ZDI-CAN-766: SVG ForeignObject Rendering Layout Vulnerability | - | 2016-10-02 |
| 43322 | [MD audit] Problems with video messages and sizes | - | 2016-10-02 |
| 257892 | Security: local user can crash a system service daemon, causing DOS | - | 2016-10-02 |
| 257852 | FileUtilitiesMessageFilter::OnOpenFile insufficient permission checks | - | 2016-10-02 |
| 257357 | Heap-use-after-free in WebCore::CSSFontFace::setLoadState | - | 2016-10-02 |
| 257353 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::destroyShadowSubtree | - | 2016-10-02 |
| 257748 | Security: Origin bypass by writing window.frames[i] | $500 | 2016-10-02 |
| 257875 | UNKNOWN in _getKeywords | - | 2016-10-02 |
| 257363 | Security: ANGLE libGLESv2 Integer Overflow | $1,337 | 2016-10-02 |
| 256724 | Remove the RELOAD exception for validating 1993 search chains | - | 2016-10-02 |
| 257347 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue | - | 2016-10-02 |
| 257348 | ASSERTION FAILED: !m_hasAXObject, Heap-use-after-free in WebCore::AccessibilityRenderObject::remoteSVGRootElement | - | 2016-10-02 |
| 256531 | Issues with HSTS / HPKP state tracking | - | 2016-10-02 |
| 257262 | Security: UAF in content::WebContentsObserver::web_contents() | - | 2016-10-02 |
| 256288 | Security:Quota Management API's bug | - | 2016-10-02 |
| 255934 | ASSERTION FAILED: width == frameRect.width(), UNKNOWN in WebCore::WEBPImageDecoder::applyPostProcessing | - | 2016-10-02 |
| 256013 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImages | - | 2016-10-02 |
| 255931 | Heap-use-after-free in qcms_profile_from_memory | - | 2016-10-02 |
| 255524 | Heap-use-after-free in content::RenderProcessHostImpl::ProcessDied | - | 2016-10-02 |
| 256020 | Pasting a URL into the infobar, then hitting enter does not cause a scroll to the left | - | 2016-10-02 |
| 256057 | going into fullscreen can be performed without even being in the foreground | - | 2016-10-02 |
| 256280 | Security: Linux kernel perf interface allows tracing of setuid processes | - | 2016-10-02 |
| 255932 | Heap-use-after-free in WTF::KeyValuePair<WTF::StringImpl*, WTF::RefPtr<WebCore::KeyframeAnimation> >* WTF::HashTable<WTF::S | - | 2016-10-02 |
| 255523 | Security: X client library bugs allow malicious X servers to attack clients | - | 2016-10-02 |
| 254728 | Heap-use-after-free in WebCore::AudioBufferSourceNode::renderFromBuffer | - | 2016-10-02 |
| 254460 | Heap-buffer-overflow in url_parse::ExtractFileName | - | 2016-10-02 |
| 254159 | Security: Chrome shared memory file can be world readable and lacks security checks when opening existing mappings. | $500 | 2016-10-02 |
| 253550 | ASSERTION FAILED: isMainThread(), Heap-use-after-free in WebCore::WaveShaperDSPKernel::lazyInitializeOversampling | $500 | 2016-10-02 |
| 253481 | Security: Insecure page shown as secure (insecure inlines and named anchors) | - | 2016-10-02 |
| 255165 | Heap-use-after-free in content::WebPluginProxy::Paint | - | 2016-10-02 |
| 254928 | Heap-use-after-free in net::HostResolverImpl::Job::OnDnsTaskFailure | - | 2016-10-02 |
| 254783 | Heap-use-after-free in WebCore::RenderObject::destroyAndCleanupAnonymousWrappers | $1,000 | 2016-10-02 |
| 252712 | Security: Use-after-free in RadioInputType::handleKeydownEvent | - | 2016-10-02 |
| 252216 | Security: spawn multiple windows in response to a single user interaction | - | 2016-10-02 |
| 252062 | Security: an attacker can sign-in a victim to his own account. | - | 2016-10-02 |
| 252034 | Security: NPAPI extension can be synced | - | 2016-10-02 |
| 252848 | SpeechRecognitionManagerImpl::SessionStart: vector::front() on an empty vector. | - | 2016-10-02 |
| 252888 | Security: <input type="file" directory> can trick user into uploading their entire Download/Desktop folder. | $1,000 | 2016-10-02 |
| 250003 | Use-after-free by navigating out a document during form validation message is shown | - | 2016-10-02 |
| 249854 | MediaStreamHostMsg_GenerateStream: validate audio_type / video_type enums | - | 2016-10-02 |
| 249640 | Heap-use-after-free in WebCore::Node::setNeedsStyleRecalc | - | 2016-10-02 |
| 252010 | Chromium sync session fixation + code execution | $21,500 | 2016-10-02 |
| 249335 | Flash settings menu vulnerable to clickjacking | - | 2016-10-02 |
| 251711 | Security: SVG Filter Timing Attack | - | 2016-10-02 |
| 249502 | Security: (Shared) (WebSQL) Worker races cause invalid pointers in DatabaseObserver::databaseClosed and DatabaseObserver::reportOpenDatabaseResult | $1,000 | 2016-10-02 |
| 249199 | Heap-use-after-free in WebCore::ApplyStyleCommand::removeInlineStyle | - | 2016-10-02 |
| 248960 | Heap-use-after-free in gfx::RenderTextWin::GetGlyphBounds | - | 2016-10-02 |
| 248950 | Heap-use-after-free in WebCore::Document::dispose | - | 2016-10-02 |
| 248843 | Heap-use-after-free in WebCore::StyleResolver::loadPendingImages | - | 2016-10-02 |
| 248840 | Heap-use-after-free in WebCore::RenderBlock::willBeDestroyed | - | 2016-10-02 |
| 249246 | Security: Open in incognito window doesn't work in panel. | - | 2016-10-02 |
| 249064 | IndexedDBHostMsg_DatabaseGet: validate params.object_store_id | - | 2016-10-02 |
| 247964 | Stack-buffer-overflow in cricket::ToString | - | 2016-10-02 |
| 248023 | ASSERTION FAILED: m_path, UNKNOWN in SkPath::isEmpty | - | 2016-10-02 |
| 42980 | Sandboxed iframes should not autocomplete/autofill unless allow-same-origin set | - | 2016-10-02 |
| 42765 | top.close() is allowed on iframe@sandbox when allow-same-origin is not set | - | 2016-10-02 |
| 42723 | Table layout crash bug from wushi | $500 | 2016-10-02 |
| 42578 | Navigation bar problem | - | 2016-10-02 |
| 42575 | sessionStorage is shared on iframe@sandbox | - | 2016-10-02 |
| 42574 | Sandboxed iframes should not allow navigation to history forward,back without allow-top-navigation set. | - | 2016-10-02 |
| 42538 | segfault in net::X509Certificate::Verify [Linux] | - | 2016-10-02 |
| 42396 | Security: WebKit: WebCore::WebGLUnsignedIntArrayInternal::getCallback ReadAV@Arbitrary (deef89ee3d0345edebeaf13cf974c47c) | - | 2016-10-02 |
| 42391 | Chromium exposes file paths when dropping files | - | 2016-10-02 |
| 42356 | User scripts can access chrome:// URLs | - | 2016-10-02 |
| 42755 | Merge fix for WebKit CSS hover security bug to 375 | - | 2016-10-02 |
| 42736 | Memory corruption (read random system memory) or crash | $500 | 2016-10-02 |
| 42300 | Memory corruption / corrupt function pointer usage with bad AAC SBR | - | 2016-10-02 |
| 42294 | WebCore::FontFallbackList::determinePitch memory corruption (0b4c05aab686a31bc4954a5bd6bae27b) | $500 | 2016-10-02 |
| 41878 | Problemas para abrir paginas webs | - | 2016-10-02 |
| 41778 | "Go To" right click context menu option can open arbitary urls like chrome:// file:// etc. | - | 2016-10-02 |
| 41654 | Security: Permanent Clipboard Hijack | - | 2016-10-02 |
| 41469 | Drag and drop bad reference counting leads to re-use of freed memory: WebCore..String..length ReadAV@Arbitrary (394bb1a56acd66a43221b2a08fa5b25a) | - | 2016-10-02 |
| 42306 | Possible num_patches array indexing errors in AAC SBR | - | 2016-10-02 |
| 42228 | Security: a malicious page may gain access to context of an extension's content script | - | 2016-10-02 |
| 41334 | Security: Selecting a address label in an address form field ALSO fills the default credit card | - | 2016-10-02 |
| 41330 | Security: Label Name truncation with long field values leading to autofill data theft | - | 2016-10-02 |
| 41265 | Security: Clicking an address form field shows credit card labels and can fill credit card fields. | - | 2016-10-02 |
| 40801 | OOB Array Indexing Bug | - | 2016-10-02 |
| 41428 | MALWARE | - | 2016-10-02 |
| 41427 | Security: Autofill does not store sensitive data like cc info as encrypted on disk, should mimic password manager | - | 2016-10-02 |
| 40628 | WebKit: WebCore::PageGroupLoadDeferrer::PageGroupLoadDeferrer ReadAV@NULL (7a3291a05aead0cc3a4bc8a6b440d145) | - | 2016-10-02 |
| 40605 | Redirecting to a data URI without a / in the data section crashes the entire browser | - | 2016-10-02 |
| 40575 | An HTTP page loaded quickly after NTP can gain DOMUI bindings privilege | - | 2016-10-02 |
| 40487 | <video> inside <foreignObject> inside <svg> inside <img> --> crash | - | 2016-10-02 |
| 40445 | Cross Origin Bypass using iframe & " " on JAVASCRIPT URI | $1,000 | 2016-10-02 |
| 40219 | Security: logged into google account but got gmail account | - | 2016-10-02 |
| 40173 | Termination bugs in GpuProcessHost | - | 2016-10-02 |
| 40147 | Security: XSS issue in the FTP parser | - | 2016-10-02 |
| 40635 | Security: v8: WebKitPoint() memory corruption | $500 | 2016-10-02 |
| 40137 | Security: XSS in net-internals | - | 2016-10-02 |
| 39985 | Cross-origin bypass: Javascript URL can be set in iframe.src via numerous DOM aliases (via Node and NamedNodeMap) | $1,000 | 2016-10-02 |
| 40138 | Security: XSS in chrome://downloads | - | 2016-10-02 |
| 39861 | Cross-origin image theft via SVGs as a canvas pattern | - | 2016-10-02 |
| 40136 | Security: Path Traversal in Devtools | - | 2016-10-02 |
| 39698 | Security: Synchronous preflight XHR allows arbitrary XSRF | - | 2016-10-02 |
| 39660 | Need to merge fix for CSSPrimitiveValue::setFloatValue() type confusion error | - | 2016-10-02 |
| 39443 | crash with form tag | $500 | 2016-10-02 |
| 39303 | icudt42.dll does not support ASLR(on Win7/Vista) | - | 2016-10-02 |
| 39277 | Browser GDI crash with excessive downloads. | - | 2016-10-02 |
| 38937 | show bug | - | 2016-10-02 |
| 38920 | extensions can circumvent access restrictions by over-writing chromeHidden.event.dispatchJSON | - | 2016-10-02 |
| 38890 | "AutoFill Profiles"-feature information disclosure issue | - | 2016-10-02 |
| 39740 | Plugins are not always blocked by content settings | - | 2016-10-02 |
| 39639 | url redirect | - | 2016-10-02 |
| 38650 | Chrome downladed XP Defender Pro java based virus from a website | - | 2016-10-02 |
| 38512 | libpng < (1.4.1|1.2.43) suffer DoS issues (CVE-2010-0205) | - | 2016-10-02 |
| 38310 | Security: *.kaiserpermanente.org sites report SSL Error (certificate failures), only on Linux | - | 2016-10-02 |
| 38749 | HTTPS | - | 2016-10-02 |
| 38845 | Out of bounds array read in FTP network transaction | - | 2016-10-02 |
| 38550 | Mac: Don't send client cert before verifying received server cert | - | 2016-10-02 |
| 38238 | Reproducible renderer crash on javascript | - | 2016-10-02 |
| 266922 | Security: Address bar spoofing possible after navigating to an unhandled protocol | - | 2016-10-02 |
| 266364 | Heap-use-after-free in WebCore::DocumentLoader::handleSubstituteDataLoadNow | - | 2016-10-02 |
| 266346 | Widevine CDM is running with excessive permissions | - | 2016-10-02 |
| 265930 | V8 SMI-only array optimizations misbehave with arrays created using the Array constructor of a different document | - | 2016-10-02 |
| 265894 | UNKNOWN in v8::internal::JSObject::SetPropertyForResult | - | 2016-10-02 |
| 265838 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | $2,000 | 2016-10-02 |
| 266729 | strongswan denial-of-service vulnerability (CVE-2013-5018) | - | 2016-10-02 |
| 266593 | ASSERTION FAILED: !element || element->hasTagName(summaryTag), UNKNOWN in WebCore::DetailsMarkerControl::summaryElement | - | 2016-10-02 |
| 265221 | Security: URL spoof with http status 204 | $500 | 2016-10-02 |
| 264988 | Chrome webrtc crashes if i try to remove remote video track in peer connection. | - | 2016-10-02 |
| 264607 | SyzyASAN: Heap-use-after-free in GrTextureAccess::reset | - | 2016-10-02 |
| 264574 | ASSERTION FAILED: !renderer->needsLayout(), Heap-use-after-free in WebCore::RenderBlock::LineBreaker::nextSegmentBreak | - | 2016-10-02 |
| 265731 | Security: mach_override_ptr maps rwx pages at fixed address and leaves PROT_WRITE on text pages | - | 2016-10-02 |
| 265493 | use-after-free on content::GpuVideoDecodeAcceleratorHost::OnErrorNotification | - | 2016-10-02 |
| 264211 | ASSERTION FAILED: run.charactersLength() >= run.length(), Heap-buffer-overflow in WebCore::Font::characterRangeCodePath | - | 2016-10-02 |
| 263811 | UNKNOWN in v8::internal::Heap::AllocateJSObject | - | 2016-10-02 |
| 263878 | Security: kernel CVE-2013-4125 fib6_add_rt2node | - | 2016-10-02 |
| 264212 | Heap-use-after-free in WebCore::Node::setCustomElementState | - | 2016-10-02 |
| 263810 | ASSERTION FAILED: !object || object->isRenderBlock(), UNKNOWN in WebCore::RenderBox::containingBlockLogicalHeightForPositioned | - | 2016-10-02 |
| 264504 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | $2,000 | 2016-10-02 |
| 263923 | Heap-use-after-free in WebCore::Scrollbar::invalidateRect | - | 2016-10-02 |
| 263214 | Security: SSLPolicy isn't checking the error associated with a saved exception | - | 2016-10-02 |
| 263178 | Heap-use-after-free in content::IndexedDBDatabase::DeleteDatabase | - | 2016-10-02 |
| 262653 | Heap-use-after-free in WebCore::RootInlineBox::closestLeafChildForPoint | $1,000 | 2016-10-02 |
| 263386 | ASSERTION FAILED: !node || node->isShadowRoot(), UNKNOWN in WebCore::EventRetargeter::eventTargetRespectingTargetRules | - | 2016-10-02 |
| 263255 | Heap-use-after-free in WebCore::RenderBlock::checkFloatsInCleanLine | - | 2016-10-02 |
| 262531 | Heap-buffer-overflow in FindSortableTop | - | 2016-10-02 |
| 262177 | Heap-use-after-free in WebCore::InlineFlowBox::deleteLine | - | 2016-10-02 |
| 261898 | Heap-buffer-overflow in autofill::AutofillPopupControllerImpl::UpdateDataListValues | $1,000 | 2016-10-02 |
| 262606 | use-after-free - speech API and window.close() ::SpeechRecognitionBubbleView::GetAnchorRect+0x23 | $1,000 | 2016-10-02 |
| 261891 | Heap-use-after-free in WebCore::RenderFlexibleBox::firstLineBoxBaseline | - | 2016-10-02 |
| 261836 | Heap-use-after-free in WebCore::Document::detach | $3,000 | 2016-10-02 |
| 261609 | Heap-use-after-free in WebCore::IdTargetObserverRegistry::removeObserver | - | 2016-10-02 |
| 261454 | Heap-use-after-free in sk_atomic_inc | - | 2016-10-02 |
| 261711 | Security: Upgrade to openssl 1.0.1e (or later) | - | 2016-10-02 |
| 260667 | Security: Content process crash on (new Window.prototype.__proto__.constructor).toString(); | - | 2016-10-02 |
| 260428 | Heap-use-after-free in WebCore::TimerBase::start | $1,000 | 2016-10-02 |
| 260165 | Heap-use-after-free in WebCore::MutationObserverRegistration::~MutationObserverRegistration | $1,000 | 2016-10-02 |
| 260156 | Heap-use-after-free in content::WebMediaPlayerImpl::paint | $1,000 | 2016-10-02 |
| 260138 | Heap-use-after-free in WebCore::ElementShadow::removeAllShadowRoots | - | 2016-10-02 |
| 260110 | Heap-use-after-free in WebCore::copyKeysToReferencingVector | $1,000 | 2016-10-02 |
| 260106 | Security: SEGV on unknown address with javascript url and __proto__ | $1,000 | 2016-10-02 |
| 260105 | Heap-use-after-free in xsltApplySequenceConstructor | $1,000 | 2016-10-02 |
| 261171 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
| 260375 | Heap-buffer-overflow in WebCore::Element::recalcStyle | $1,000 | 2016-10-02 |
| 259859 | Heap-use-after-free in content::RenderViewHostManager::ShutdownRenderViewHostsInSiteInstance | - | 2016-10-02 |
| 259669 | Security: Drag-drop an image to the desktop: adds executable file to the desktop | - | 2016-10-02 |
| 259389 | Heap-buffer-overflow in WebCore::parseDimension | - | 2016-10-02 |
| 259366 | Security: JSON.stringify does not do cross context check. | - | 2016-10-02 |
| 258771 | Lax permissions on the password database | - | 2016-10-02 |
| 258723 | Security: JPEG info leak | - | 2016-10-02 |
| 260087 | Heap-use-after-free in WebCore::IdTargetObserverRegistry::removeObserver | - | 2016-10-02 |
| 259951 | Heap-use-after-free in WebCore::RenderStyle::fontDescription | - | 2016-10-02 |
| 258419 | Heap-use-after-free in WebCore::CachedResource::cancelTimerFired | - | 2016-10-02 |
| 38066 | Exploit.IFrame.Gen | - | 2016-10-02 |
| 37876 | Issue when having saved password and favourite in the favourites bar | - | 2016-10-02 |
| 38194 | bypass the popblock | - | 2016-10-02 |
| 37841 | ĂÂżĂŸĂÂČĂÂÔöĂÂŽĂ”Ăœ chrome.exe | - | 2016-10-02 |
| 37840 | ĂÂżĂŸĂÂČĂÂÔöĂÂŽĂ”Ăœ chrome.exe | - | 2016-10-02 |
| 37826 | Need to merge fix for https://bugs.webkit.org/show_bug.cgi?id=35621 / ZDI-CAN-688 | - | 2016-10-02 |
| 37657 | Will not block all cookies when you select block all cookies | - | 2016-10-02 |
| 37479 | Merge http://trac.webkit.org/changeset/53442 | - | 2016-10-02 |
| 37447 | Google Chrome OCX Automatic Download | - | 2016-10-02 |
| 37383 | javascript: url with a leading NULL byte can bypass cross origin protection. | $1,000 | 2016-10-02 |
| 37362 | Security: Ogg Vorbis: Random crashes when playing .ogg | - | 2016-10-02 |
| 37310 | Crash in media::FFmpegDemuxer::~FFmpegDemuxer() | - | 2016-10-02 |
| 37201 | Omnibox visual spoofing with Japanese Maru | - | 2016-10-02 |
| 37827 | Need to merge fix for https://bugs.webkit.org/show_bug.cgi?id=35598 / ZDI-CAN-704 | - | 2016-10-02 |
| 37190 | Security: WebSocket: WebCore::String::isEmpty ReadAV@Arbitrary | - | 2016-10-02 |
| 37184 | Security: ff_vorbis_floor1_render_list ReadAV@Arbitrary (multiple stacks) | - | 2016-10-02 |
| 37176 | Security bugs for $500 each. | - | 2016-10-02 |
| 37061 | WebCore::SVGUseElement::updateContainerOffsets ExecAV@Arbitrary (1dc75f12fe3750aa1828ea20506a5d54) | $500 | 2016-10-02 |
| 37007 | Bypass unsafe file types dialog using extra dots at end of file name. | - | 2016-10-02 |
| 36976 | WebCore::SVGAnimationElement::calculatePercentFromKeyPoints ReadAV@NULL (00939658970e30ddcc2953e88ebb851d) | - | 2016-10-02 |
| 36774 | The 1 second timeout on safebrowsing get hash might be exploitable | - | 2016-10-02 |
| 36772 | Security: HTTP AUTH dialog spoofing using long subdomains (Windows Only) | - | 2016-10-02 |
| 36770 | HTTPS server can cause us to bypass certificate checking with NSS. | - | 2016-10-02 |
| 36715 | Phishing site seems to be able to bypass Chrome's phish warning page | - | 2016-10-02 |
| 36553 | Information Disclosure in "Web Data" | - | 2016-10-02 |
| 36277 | Passwords may be easily seen. | - | 2016-10-02 |
| 35994 | Security Issue Firefox 3.0.17 & Skype Add-on & Google Gmail | - | 2016-10-02 |
| 35979 | Security: Opening a malformed XML file causes a segmentation fault in xmlParseGetLasts. | - | 2016-10-02 |
| 35943 | [MD audit] HandleGetShaderSource Integer Underflow | - | 2016-10-02 |
| 35942 | [MD audit] DrawElements Signed Integer Vulnerability | - | 2016-10-02 |
| 35941 | [MD audit] GenGLObjects Buffer Overflow | - | 2016-10-02 |
| 35938 | [MD audit] DeleteGLObjects Buffer Overflow | - | 2016-10-02 |
| 35937 | [MD audit] GPU Signed Relatie Call Vulnerability | - | 2016-10-02 |
| 35934 | [MD audit] GPU Signed Relative Jump Vulnerability | - | 2016-10-02 |
| 35932 | [MD audit] GPU Signed Jump Vulnerability | - | 2016-10-02 |
| 35931 | [MD audit] Command Buffer Service Integer Overflow | - | 2016-10-02 |
| 35732 | Security: Renderer segfault when a malformed png file is loaded. | $500 | 2016-10-02 |
| 35649 | embed bug | - | 2016-10-02 |
| 35408 | Pls Help Google Chrome Bug | - | 2016-10-02 |
| 35936 | [MD audit] GPU Signed Call Vulnerability | - | 2016-10-02 |
| 35168 | Crash when clicking long URL with unknown scheme | - | 2016-10-02 |
| 35079 | Stale pointer in WebKit with captions | - | 2016-10-02 |
| 34834 | SSL error reported in Chrome v.4.0.249.78 (36714); OK on Firefox v.3.5.7 and I.E. v.8.0.6001.18702 | - | 2016-10-02 |
| 35366 | [MD audit] DOM tree node reference errors when manipulating DOM tree inside certain callbacks | - | 2016-10-02 |
| 34978 | WebCore::Document::recalcStyleSelector+0x7c | $500 | 2016-10-02 |
| 34765 | error en google mail de chrome | - | 2016-10-02 |
| 34800 | Security bug found in 4.0.249.78 | - | 2016-10-02 |
| 34710 | [MD audit] out-of-bounds array access in worker_process_host.cc | - | 2016-10-02 |
| 34566 | Security: WebCore::FEMorphology::apply memmove ReadAV@NULL (ec3ed2d76f7904e1c4df8ea3b1dd07e6) | - | 2016-10-02 |
| 34498 | Navigating to a cached page can result in accessing a destroyed HTMLInputElement [CVE-2010-0052] | - | 2016-10-02 |
| 34495 | Crash in XMLTokenizer::popCurrentNode if window.close() is called during parsing [CVE-2010-0048] | - | 2016-10-02 |
| 34414 | Regression:m7: Chrome Popup Blocker ByPass | - | 2016-10-02 |
| 34760 | I/O errors | - | 2016-10-02 |
| 34782 | Browser hangs | - | 2016-10-02 |
| 34721 | Long string in alert() 100% CPU DoS | - | 2016-10-02 |
| 278912 | Heap-buffer-overflow in WebCore::Element::recalcStyle | $2,000 | 2016-10-02 |
| 279263 | use-after-free in ColorChooserDialog::DidCloseDialog | $1,000 | 2016-10-02 |
| 278908 | Heap-use-after-free in WebCore::XMLDocumentParser::append | $1,000 | 2016-10-02 |
| 279286 | ASSERT: Bad cast from CSSInitialValue to CSSValueList., UNKNOWN in WebCore::CSSValue::isCFCSSValueList | - | 2016-10-02 |
| 279277 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | $2,000 | 2016-10-02 |
| 278676 | Heap-buffer-overflow in content::SiteIsolationPolicy::ShouldBlockResponse | - | 2016-10-02 |
| 278366 | Security: Page can DDOS and crash browser: while (1) window.open() | - | 2016-10-02 |
| 277656 | ASSERT: isDocumentLifecycleObserver()ASAN:SIGSEGV, UNKNOWN in WebCore::DocumentLifecycleNotifier::notifyDocumentWasDisposed | - | 2016-10-02 |
| 276368 | Heap-use-after-free in ppapi::proxy::PluginResource::NotifyInstanceWasDeleted | $1,000 | 2016-10-02 |
| 276339 | Use-after-free in content::WebPluginDelegateImpl::NativeWndProc | - | 2016-10-02 |
| 275803 | Heap-buffer-overflow on icu_46::CharsetRecog_UTF_32_BE::getChar | - | 2016-10-02 |
| 275590 | Heap-buffer-overflow in media::AudioBuffer::ReadFrames | - | 2016-10-02 |
| 276111 | ASSERTION FAILED: splineIndex < m_keySplines.size(), UNKNOWN in WebCore::SVGAnimationElement::calculatePercentForSpline | - | 2016-10-02 |
| 274843 | CORS-enabled image should fail to load when redirected with CORS failure. | - | 2016-10-02 |
| 274658 | Heap-use-after-free in PluginPlaceholder::ReplacePlugin | - | 2016-10-02 |
| 276106 | ASSERTION FAILED: actualInfo->derefObjectFunction == info.derefObjectFunction, UNKNOWN in WebCore::V8HTMLElement::createWrapper | - | 2016-10-02 |
| 276042 | Use-after-free in views::HWNDMessageHandler::_ProcessWindowMessage | - | 2016-10-02 |
| 275223 | Heap-use-after-free in WebCore::EditCommandComposition::~EditCommandComposition | - | 2016-10-02 |
| 273734 | Heap-use-after-free in WebCore::SharedStyleFinder::canShareStyleWithElement | - | 2016-10-02 |
| 273732 | Use-after-free in WebCore::GraphicsLayer::setContentsTo | - | 2016-10-02 |
| 272954 | Heap-use-after-free in WebCore::SpaceSplitString::set | - | 2016-10-02 |
| 272786 | Use-after-free in WebCore::TimerBase::stop | $2,000 | 2016-10-02 |
| 274020 | Security: Blocked popups can navigate anywhere once unblocked | - | 2016-10-02 |
| 274408 | Security: Cross-origin information should not be available via JavaScript. | - | 2016-10-02 |
| 271782 | Security: Incognito mode state not necessarily encrypted properly | - | 2016-10-02 |
| 272072 | Regression: 301 redirect to data: URLs works | - | 2016-10-02 |
| 271221 | Heap-use-after-free in WebCore::StylePendingImage::data | - | 2016-10-02 |
| 271161 | Heap-use-after-free in WebCore::AudioDSPKernelProcessor::reset | $500 | 2016-10-02 |
| 271130 | ASSERTION FAILED: !node || node->isElementNode(), UNKNOWN in WebCore::CompositeEditCommand::cloneParagraphUnderNewElement | - | 2016-10-02 |
| 271939 | Heap-use-after-free in xsltApplySequenceConstructor | $1,000 | 2016-10-02 |
| 271235 | ASSERTION FAILED: index < static_cast<unsigned>(length()), UNKNOWN in WebCore::TextIterator::characterAt | - | 2016-10-02 |
| 270272 | Heap-use-after-free in WebCore::Node::compareDocumentPositionInternal | - | 2016-10-02 |
| 270758 | Heap-use-after-free in WebCore::HRTFElevation::calculateKernelsForAzimuthElevation | $500 | 2016-10-02 |
| 269753 | Heap-use-after-free in webkitOfflineAudioContext | $500 | 2016-10-02 |
| 268565 | Security: use-after-free Speech with changing of the page | $500 | 2016-10-02 |
| 269837 | Heap-buffer-overflow in util::to_uint16_t | - | 2016-10-02 |
| 269709 | Wild-access in WTF::HashTable<WebCore::RenderObject *,WTF::KeyValuePair<WebCore::RenderObject *,WebCore::FilterEffe | - | 2016-10-02 |
| 269835 | Heap-buffer-overflow in office::doc::BxPap::Init | - | 2016-10-02 |
| 268365 | Heap-use-after-free in std::pair<WTF::KeyValuePair<WTF::StringImpl*, WebCore::Element*>*, bool> WTF::HashTable<WTF::StringI | - | 2016-10-02 |
| 267824 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
| 267068 | Heap-use-after-free in WebCore::HTMLFormControlsCollectionV8Internal::indexedPropertyGetterCallback | - | 2016-10-02 |
| 34151 | ChromeFrame: cookie policy not honored in chrome Frame | - | 2016-10-02 |
| 34135 | Browser process crash (CHECK failure) in TabStripModel::GetContentsAt(int) const | - | 2016-10-02 |
| 33906 | Why that | - | 2016-10-02 |
| 33881 | Security Bug | - | 2016-10-02 |
| 33876 | Security: LocalStorage Cross Domain Denial of Service Attack | - | 2016-10-02 |
| 33873 | Confirm Close | - | 2016-10-02 |
| 33995 | Bug ?? | - | 2016-10-02 |
| 33870 | VKontakte Checker | - | 2016-10-02 |
| 33869 | VKontakte Tools | - | 2016-10-02 |
| 33864 | chrome an chromium bug with flash | - | 2016-10-02 |
| 33834 | MISTAKE (BĂ
ÂĂÂD) | - | 2016-10-02 |
| 33952 | Infinite redirects with long URL can cause browser process OOM. | - | 2016-10-02 |
| 33872 | Chromepad | - | 2016-10-02 |
| 33830 | Confirm Close | - | 2016-10-02 |
| 33817 | ĂÂĂÂÞñĂÂșð ĂÂżĂÂĂž ĂŸĂÂĂÂșĂ»ĂÂĂÂĂ”ĂœĂžĂž | - | 2016-10-02 |
| 33791 | Trouble when opening a downloadable link | - | 2016-10-02 |
| 33738 | r | - | 2016-10-02 |
| 33736 | 333 | - | 2016-10-02 |
| 33729 | chrome an chromium bug with flash | - | 2016-10-02 |
| 33831 | some parameters not working | - | 2016-10-02 |
| 33678 | y | - | 2016-10-02 |
| 33664 | XSS Filter can disable legitimate code, creating vulnerabilities in otherwise safe webpages | - | 2016-10-02 |
| 33607 | Security: SSL with Chrome using googlewave.com on Chromium | - | 2016-10-02 |
| 33572 | Security: "Harmful websites" are allowed to initiate downloads without user intervention. | - | 2016-10-02 |
| 33508 | Https issue | - | 2016-10-02 |
| 33445 | STS design questions around probing what sites a user has been to | - | 2016-10-02 |
| 33391 | Script tags are copied and pasted into xml, making cross-domain attacks possible | - | 2016-10-02 |
| 33695 | Chrome problem. | - | 2016-10-02 |
| 33053 | Use of stale HTMLImageElement pointer in JSHTMLFormElement::nameGetter | - | 2016-10-02 |
| 32856 | Script tags are copied and pasted, making cross-domain attacks possible | - | 2016-10-02 |
| 33324 | New windows opened within ChromeFrame in full tab mode don't use the host network stack | - | 2016-10-02 |
| 32718 | Security: Cross-domain bug in password manager | $500 | 2016-10-02 |
| 32558 | auto text | - | 2016-10-02 |
| 32457 | Security: WebKit Bug 33802 - WebCore::RenderMenuList::setText ExecAV@Arbitrary (fe810d95ab2c1eef13e951397ed944ce) | - | 2016-10-02 |
| 32455 | ValidityState can hold a stale pointer to control | - | 2016-10-02 |
| 32309 | Stylesheet URL property leaks redirection target | - | 2016-10-02 |
| 32207 | The CLD (Compact Language Detection) code is run in the browser, it should run in the renderer. | - | 2016-10-02 |
| 32014 | [MD audit] [clipboard] Type confusion possible in Linux clipboard implementation | - | 2016-10-02 |
| 31953 | Resolve URL Before Proxy | - | 2016-10-02 |
| 32915 | [MD audit] [Window Sandbox] CrossCallParamsEx::CreateFromBuffer() integer overflow | - | 2016-10-02 |
| 31935 | appcache: https servers shouldn't be able to store no-store pages from other servers | - | 2016-10-02 |
| 31880 | [MD audit] [plugins] Sandbox Violation: Raw pointer from renderer manipulated in plugin process | - | 2016-10-02 |
| 31568 | Need to merge WebKit fix for ZDI-CAN-632 to Beta branch | - | 2016-10-02 |
| 31554 | Invalid Read (possible code execution): Empty name parameter passed to v8::internal::LoadIC::Load() | - | 2016-10-02 |
| 31542 | Use after free crash in RTL text handling | - | 2016-10-02 |
| 31517 | ChildProcessSecurityPolicy::CanRequestURL recusion stack exhaustion in URL parsing with nested protocols | - | 2016-10-02 |
| 31364 | [MD audit] [IPC] problems calling resize() on vectors with no sanitization | - | 2016-10-02 |
| 31307 | [MD audit] [RPC] More errors deserializing SkBitmaps!! | - | 2016-10-02 |
| 31298 | [MD audit] [RPC] Integer overflow in clipboard image deserialization | - | 2016-10-02 |
| 31293 | Audio TAG MP3 plays noise burst at beginning | - | 2016-10-02 |
| 31267 | Security: Popup & Focus URL Hijacking from ha.ckers.org, exploit works with chrome autodownload | - | 2016-10-02 |
| 31144 | warn when downloading common Linux package files such as .deb | - | 2016-10-02 |
| 31943 | Bypass of HTML5 iframe sandbox attribute (can set window.top.location) | - | 2016-10-02 |
| 31692 | Bug 33266 - WebCore::InlineFlowBox::determineSpacingForFlowBoxes ReadAV@NULL (43c64e8abbda6766e5f5edbd254c2d57) | - | 2016-10-02 |
| 30972 | Google Chrome XSS through MS Word Script Execution Object | - | 2016-10-02 |
| 31009 | [MD audit] [V8]: integer errors lead to dangerous crashes in memory allocators | - | 2016-10-02 |
| 31012 | [MD audit] [3d] | - | 2016-10-02 |
| 30937 | Possible to execute script on unpermitted domains using chrome.tabs.executeScript() | - | 2016-10-02 |
| 294242 | Url spoof with play store url | - | 2016-10-02 |
| 294206 | Heap-use-after-free in WebCore::IDBDatabase::transactionFinished | - | 2016-10-02 |
| 294202 | ASSERTION FAILED: hasRareData(), UNKNOWN in WebCore::Node::rareData | - | 2016-10-02 |
| 294023 | Heap-buffer-overflow in bool WebCore::SelectorChecker::checkOne<WebCore::DOMSiblingTraversalStrategy> | - | 2016-10-02 |
| 294464 | Heap-use-after-free in WebCore::SVGLength::SVGLength | - | 2016-10-02 |
| 294456 | Heap-use-after-free in WebCore::canMergeLists | $2,000 | 2016-10-02 |
| 293521 | Heap-use-after-free in WebCore::CSSFontSelector::dispatchInvalidationCallbacks | - | 2016-10-02 |
| 293127 | Use-after-free in WTF::HashTable<int,WTF::KeyValuePair<int,WTF::RefPtr<WebCore::CalculationValue> >,WTF::KeyValuePairK | - | 2016-10-02 |
| 292679 | Heap-use-after-free in Pickle::~Pickle | - | 2016-10-02 |
| 292422 | ASSERTION FAILED: m_pendingActivityCount > 0, Heap-use-after-free in WebCore::XMLHttpRequest::open | $1,000 | 2016-10-02 |
| 291854 | ASSERTION FAILED: !node || node->hasTagName(HTMLNames::metaTag), UNKNOWN in WebCore::TextAutosizer::detectContentType | - | 2016-10-02 |
| 290566 | Heap-use-after-free in WTF::equalNonNull | $1,000 | 2016-10-02 |
| 293707 | ASSERTION FAILED: !value || value->isValueList(), UNKNOWN in WebCore::FontFace::createCSSFontFace | - | 2016-10-02 |
| 293534 | Heap-use-after-free in WebCore::Document::updateLayout | $3,000 | 2016-10-02 |
| 290165 | ASSERTION FAILED: !needsLayout(), UNKNOWN in WebCore::RenderTableSection::paint | $500 | 2016-10-02 |
| 290163 | Heap-use-after-free in WebCore::InputMethodContext::selectedSegment | - | 2016-10-02 |
| 289680 | Heap-buffer-overflow in PL_strdup | - | 2016-10-02 |
| 289648 | Security: work around user gesture requirement | - | 2016-10-02 |
| 288977 | Security: Insecure root-privileged file touch in /home/chronos by activate_date_spring.conf | - | 2016-10-02 |
| 288797 | Heap-use-after-free in WebCore::TextFieldInputType::updateInnerTextValue | - | 2016-10-02 |
| 290396 | Heap-use-after-free in WebCore::FrameLoader::load | - | 2016-10-02 |
| 288771 | Heap-use-after-free in WebCore::SVGMatrixV8Internal::rotateMethodCallback | - | 2016-10-02 |
| 288761 | Heap-use-after-free in WebCore::Document::updateLayout | - | 2016-10-02 |
| 286975 | Heap-use-after-free in WebCore::Node::containsIncludingHostElements | $2,000 | 2016-10-02 |
| 286621 | Heap-use-after-free in BubbleGtk::Close | - | 2016-10-02 |
| 286617 | Use-after-free in WebCore::RenderObject::previousInPreOrder | - | 2016-10-02 |
| 286444 | Crash due to a bug in CoreText with some Arabic strings on Mac OS 10.8-10.8.4 and iOS 6 | - | 2016-10-02 |
| 286414 | Heap-use-after-free in WTF::KeyValuePair<WebCore::Resource*, WTF::RefPtr<WebCore::ResourceTimingInfo> >::~KeyValuePair | $1,000 | 2016-10-02 |
| 286368 | ASSERT: Bad cast from Element to HTMLDetailsElement., UNKNOWN in Bad cast from Element to HTMLDetailsElement | - | 2016-10-02 |
| 288754 | Security: OOB in xfer32 in SKIA | - | 2016-10-02 |
| 285783 | Heap-buffer-overflow in indic_ot_reorder | - | 2016-10-02 |
| 285578 | Heap-use-after-free in gpu::CommandBufferHelper::~CommandBufferHelper | - | 2016-10-02 |
| 285380 | Heap-use-after-free in content::QuotaDispatcherHost::RequestQuotaDispatcher::DidFinish | - | 2016-10-02 |
| 284792 | FileAPIMessageFilter::OnOpenFile opens files with greater permissions than checked | - | 2016-10-02 |
| 284786 | Heap-use-after-free in content::WebAudioSourceProviderImpl::provideInput | $500 | 2016-10-02 |
| 284785 | Heap-use-after-free in WebCore::ConvolverNode::tailTime | $500 | 2016-10-02 |
| 285787 | Heap-use-after-free in WebCore::ApplyBlockElementCommand::rangeForParagraphSplittingTextNodesIfNeeded | $1,000 | 2016-10-02 |
| 285742 | Heap-use-after-free in void url_parse:: | - | 2016-10-02 |
| 282925 | ASSERTION FAILED: !needsLayout(), UNKNOWN in WebCore::RenderSVGResourceClipper::applyClippingToContext | $500 | 2016-10-02 |
| 282923 | Heap-use-after-free in webrtc::voe::Channel::SendRTCPPacket | - | 2016-10-02 |
| 282922 | Heap-use-after-free in WebCore::HTMLMediaElement::parseAttribute | - | 2016-10-02 |
| 282738 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in WebCore::InlineTextBox::constructTextRun | - | 2016-10-02 |
| 282736 | Javascript execution bug introduced with Chrome 29.0.1547.57 | $1,000 | 2016-10-02 |
| 284532 | ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::ViewportStyleResolver::getViewportLengthValue | - | 2016-10-02 |
| 280352 | ASSERTION FAILED: !node || node->hasTagName(HTMLNames::tdTag) || node->hasTagName(HTMLNames::thTag), UNKNOWN in WebCore::AccessibilityTable::isDataTable | - | 2016-10-02 |
| 282425 | Heap-use-after-free in WebCore::RenderLayer::renderer | - | 2016-10-02 |
| 281256 | Address bar spoofing with window.open() + 204 No Content | $2,000 | 2016-10-02 |
| 280729 | Security: Linux HID flaws | - | 2016-10-02 |
| 280552 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 280512 | Possible to hide current address by going to "tel:" link and then a "#" link | - | 2016-10-02 |
| 280470 | Security: Closing a webview while it is loading crashes the OS sessions. | - | 2016-10-02 |
| 281480 | Heap-buffer-overflow in WebCore::ReverbConvolverStage::ReverbConvolverStage | $500 | 2016-10-02 |
| 280170 | Heap-use-after-free in WebRtcNetEQ_RecInRTPStruct | - | 2016-10-02 |
| 280128 | ChromeView segfaults writing illegally during Vellamo test with drawPosTextH | - | 2016-10-02 |
| 282088 | Heap-use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | $1,000 | 2016-10-02 |
| 279643 | Heap-use-after-free in cricket::StreamSelector::Matches | - | 2016-10-02 |
| 279642 | Heap-use-after-free in non-virtual thunk to cricket::TransportChannelProxy::OnMessage | - | 2016-10-02 |
| 279640 | UNKNOWN in extract_image_data | - | 2016-10-02 |
| 279639 | Heap-use-after-free in cricket::Connection::local_candidate | - | 2016-10-02 |
| 30794 | Out of bounds read when processing SVG feColorMatrix filter | - | 2016-10-02 |
| 30682 | Disable the null encryption and weak encryption TLS/SSL cipher suites | - | 2016-10-02 |
| 30660 | window.open() Method Javascript Same-Origin Policy Violation | $1,000 | 2016-10-02 |
| 30659 | Security: restrict sqlite functions in the function authorizer | - | 2016-10-02 |
| 30525 | Merge HTMLParser security fix from WebKit | - | 2016-10-02 |
| 30510 | Security: invalid pointer access when calling HTML5 Web Database REGEXP() function with just one argument | - | 2016-10-02 |
| 30146 | chrome.tabs.executeScriptInTab allows running script in the gallery | - | 2016-10-02 |
| 30080 | Extension pop-up page is loaded into main window | - | 2016-10-02 |
| 30078 | Web Workers abuse - opt in required? | - | 2016-10-02 |
| 29932 | Security: Websockets - malformed URL freezes browser | - | 2016-10-02 |
| 29920 | Referer: header is sent when redirect from https to http | - | 2016-10-02 |
| 30079 | Security SafeBrowsingService pure virtual function call and memory corruption | - | 2016-10-02 |
| 29854 | Security: WebKit Bug 32316 - WebCore::RenderObject::arenaDelete ExecAV@??? (292164e5b2ee939ff3ddf062439c2a3e) | - | 2016-10-02 |
| 29828 | Security: sandbox bypass due to directory traversal opening Web Database files | - | 2016-10-02 |
| 29645 | Prevent exposing autocomplete values via Javascript | - | 2016-10-02 |
| 29577 | Crash on complicated @font-face rule | - | 2016-10-02 |
| 29543 | Bug | - | 2016-10-02 |
| 29914 | DNS queries not forwarded through SOCKS v5 proxies | - | 2016-10-02 |
| 29657 | [MD audit] [NPAPI] Unsafe use of raw pointers between processes | - | 2016-10-02 |
| 29292 | HTTPS pages contain warning about not being secure. | - | 2016-10-02 |
| 28811 | Security: WebKit Bug 31886 - Notification::Notification m_presenter reuse of freed memory | - | 2016-10-02 |
| 28804 | [MD audit] [Window Sandbox] PreProcessName() Race Condition | - | 2016-10-02 |
| 28798 | [MD audit] [Window Sandbox] Integrity Level Race Condition | - | 2016-10-02 |
| 28606 | Security: Chrome/chromium crash in Skia (CSS) due to flashplugin crash | - | 2016-10-02 |
| 28582 | Out-of-bounds read in memcpy() upon one line CSS - sometimes OOM too | - | 2016-10-02 |
| 29294 | Security: What about support for the Green Address Bar? (SSL EV...) | - | 2016-10-02 |
| 28880 | Security: Crash in WebCore/platform/graphics/chromium/FontLinux.cpp:355 (WebCore::TextRunWalker::setupFontForScriptRun) | - | 2016-10-02 |
| 28566 | Security: Crash when opening a corrupted GIF image | - | 2016-10-02 |
| 28449 | Linear gradient on a table row crashes Chromium | - | 2016-10-02 |
| 28360 | Security: Chromium/chrome crash in WebCore::RenderMarquee::computePosition | - | 2016-10-02 |
| 28346 | Security: net::HttpStreamParser::DoReadBodyComplete OOM browser crash using Content-Length | - | 2016-10-02 |
| 28250 | Chrome/chromium crash in Skia (memset) due to excessive stroke | - | 2016-10-02 |
| 28043 | Security: LocalStorage does not account the key strings in the quota enforcement | - | 2016-10-02 |
| 28015 | Security: notifications can pop-up unsolicited windows | - | 2016-10-02 |
| 28574 | Security: Memory corruption in WebCore::ResourceLoader | - | 2016-10-02 |
| 27916 | Bounds error in skAlphaRuns causes renderer hang | - | 2016-10-02 |
| 27544 | HTML notifications should only allow http URLs as content (or not have elevated privileges for data: / javascript:) | - | 2016-10-02 |
| 27501 | Security: Bad reference counting in WTF:: PassRefPtr leads to use after free | - | 2016-10-02 |
| 26771 | Let users choose the default privacy behaviour (like address bar and other stuff ... ) IMPORTANT !!! | - | 2016-10-02 |
| 26770 | change default beaviour of bar: let choose users about their privacy chroium privacy | - | 2016-10-02 |
| 26585 | Security: Flash does not lose focus, which allows things like key logging | - | 2016-10-02 |
| 26179 | Security: Chromium bug for gears fts2 security vulnerability | - | 2016-10-02 |
| 28014 | Security: crash when requestPermission() called | - | 2016-10-02 |
| 27509 | Security: HttpStreamParser::DoReadBodyComplete buffer overflow. | - | 2016-10-02 |
| 24733 | Browser crash in icu processing text from Japanese page | - | 2016-10-02 |
| 26129 | Security: MSVR report: Chrome Frame allows x-domain data theft in IE | $500 | 2016-10-02 |
| 24375 | Unbounded read (possible write) in SDCH header parsing | - | 2016-10-02 |
| 23979 | Security: add other common HTML extensions to the dangerous extensions list | - | 2016-10-02 |
| 23693 | Security: sanitize URLs better before creating desktop shortcuts | - | 2016-10-02 |
| 24646 | Security: Skia memory corruption with x<0 in SkA*_Blitter::blitH | - | 2016-10-02 |
| 25578 | No more symbolic links in the .app (en.lproj -> en_US.lproj) | - | 2016-10-02 |
| 24486 | Chrome does not checksum downloaded .bdic files; Leads to crashes, possible exploits. | - | 2016-10-02 |
| 22846 | ChromeFrame does not respect IE Privacy features | - | 2016-10-02 |
| 23188 | Gears DLL is not marked at NX compatible | - | 2016-10-02 |
| 22115 | Two pages munged together if an anchor is clicked during unload | - | 2016-10-02 |
| 22721 | Security: Chrome Frame 301/302 redirect URL spoofing | - | 2016-10-02 |
| 23189 | avcodec-52.dll is not marked NX, SafeSEH or DBCompat | - | 2016-10-02 |
| 23006 | Security: Chrome Frame links circumvent IE8's SmartScreen | - | 2016-10-02 |
| 22451 | Use-after-free in IPC::Channel::ChannelImpl::ProcessOutgoingMessages() in UtilityProcessHostTest.ExtensionUnpacker | - | 2016-10-02 |
| 21354 | ISO-2022-CN and ISO-2022-CN-Ext are not supported leading to a potential XSS attack | - | 2016-10-02 |
| 21338 | Same Origin Policy Bypass via getSVGDocument() method. | $500 | 2016-10-02 |
| 21489 | Linux create fail for /tmp/chrome_shutdown_ms.txt in mixed user environment | - | 2016-10-02 |
| 21770 | Security: ParseFTPList buffer fencepost, integer underflow | - | 2016-10-02 |
| 21771 | Security: ParseFTPList integer underflow | - | 2016-10-02 |
| 21385 | No prompt when installing extension from odd content type | - | 2016-10-02 |
| 21242 | Merge webkit.org@48142 to mstone-3 | - | 2016-10-02 |
| 21238 | security: Content-Type: application/rss+xml being rendered as active content | - | 2016-10-02 |
| 21128 | XMLHttpRequest allows loading from another origin | - | 2016-10-02 |
| 309452 | Heap-use-after-free in WebCore::CSSSelectorList::selectorAt | - | 2016-10-02 |
| 309453 | Heap-use-after-free in WebCore::RenderBlockFlow::computeBlockDirectionPositionsForLine | - | 2016-10-02 |
| 309201 | Heap-buffer-overflow in WebCore::RenderView::positionDialog | - | 2016-10-02 |
| 308988 | Use-after-free in v8::HandleScope::HandleScope | - | 2016-10-02 |
| 307159 | Response splitting with 302 redirects allows chrome sync session fixation | $1,337 | 2016-10-02 |
| 306346 | Heap-use-after-free in WebCore::ResourceLoader::requestSynchronously | - | 2016-10-02 |
| 306694 | Crash in WebKit::WebHelperPluginImpl::closeHelperPlugin() | - | 2016-10-02 |
| 305951 | Security: Don't send encrypted extensions (Channel ID, NPN,OBC) when server certificate is untrusted | $1,000 | 2016-10-02 |
| 305904 | Heap-use-after-free in WebCore::RenderBlock::determineStartPosition | - | 2016-10-02 |
| 305368 | Use-after-free in printing::PrintingContextWin::AskUserForSettings | - | 2016-10-02 |
| 306802 | Heap-buffer-overflow in WebCore::Font::characterRangeCodePath | - | 2016-10-02 |
| 306803 | Heap-use-after-free in content::RenderViewImpl::OnMessageReceived | - | 2016-10-02 |
| 306255 | content_shell crash with --dump-render-tree and non-ASCII content | - | 2016-10-02 |
| 305278 | Heap-use-after-free in WebCore::HTMLMediaElement::contextDestroyed | - | 2016-10-02 |
| 305220 | TLS session caching occurs before certificate validation | $500 | 2016-10-02 |
| 305080 | Heap-use-after-free in WebCore::XMLHttpRequest::~XMLHttpRequest | - | 2016-10-02 |
| 304967 | Use-after-free in content::GpuChannelHost::Send | - | 2016-10-02 |
| 305350 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGTransform>::detachWrapper | - | 2016-10-02 |
| 304787 | Heap-use-after-free in content::PluginURLFetcher::OnReceivedData | $500 | 2016-10-02 |
| 304547 | Security: popups opened in fullscreen mode are opened as popunders | - | 2016-10-02 |
| 304398 | WebRTCIdentityStore should delete expired identities | - | 2016-10-02 |
| 305279 | Heap-use-after-free in WebCore::GraphicsLayer::setContentsClippingMaskLayer | - | 2016-10-02 |
| 304791 | Multiple libvpx potential security issues | - | 2016-10-02 |
| 303927 | Use after free with new media::ScopedPtrAVFreeFrame | - | 2016-10-02 |
| 303657 | Heap-use-after-free in WebCore::HTMLFormElement::submit | - | 2016-10-02 |
| 303477 | ASSERTION FAILED: !node || node->isTextNode(), UNKNOWN in WebCore::RenderBlock::updateFirstLetter | - | 2016-10-02 |
| 303476 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGNumber>::detachWrapper | - | 2016-10-02 |
| 303232 | ASSERT: Bad cast from Event to GestureEvent., UNKNOWN in Bad cast from Event to GestureEvent | - | 2016-10-02 |
| 304226 | Security: Address bar spoofing on Android with window.open() + 204 No Content | - | 2016-10-02 |
| 303772 | Heap-use-after-free in WebCore::SliderThumbElement::dragFrom | - | 2016-10-02 |
| 302539 | Heap-buffer-overflow in ssl3_HandleHandshakeMessage | - | 2016-10-02 |
| 301941 | ASSERTION FAILED: npObject, UNKNOWN in content::NPObjectProxy::NPNEvaluate | - | 2016-10-02 |
| 301196 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in WebCore::InlineTextBox::paint | - | 2016-10-02 |
| 300892 | Heap-use-after-free in WebCore::Document::updateHoverActiveState | - | 2016-10-02 |
| 302724 | Content Script Shared Memory Buffer is writable | - | 2016-10-02 |
| 302810 | ASSERT: Bad cast from Event to TouchEvent., UNKNOWN in Bad cast from Event to TouchEvent | - | 2016-10-02 |
| 302007 | Security: Chrome can be easily made to stop working | - | 2016-10-02 |
| 299892 | HTTP 1xx response handling code allows a website to read memory from the main process' heap. | $4,000 | 2016-10-02 |
| 299835 | libjpeg_turbo huffval infoleak | - | 2016-10-02 |
| 299803 | Heap-use-after-free in WebCore::RenderLayerModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 298660 | Sparse file confuses temporary storage quota | - | 2016-10-02 |
| 297976 | Heap-buffer-overflow in bool WebCore::SelectorChecker::checkOne<WebCore::DOMSiblingTraversalStrategy> | - | 2016-10-02 |
| 300129 | Heap-use-after-free in content::RenderViewHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
| 299993 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlock::createLineBoxes | - | 2016-10-02 |
| 297556 | Heap-use-after-free in content::IndexedDBBackingStore::Transaction::Begin | - | 2016-10-02 |
| 297478 | Heap-use-after-free in WebCore::HTMLFormElement::submit | $2,000 | 2016-10-02 |
| 296690 | UNKNOWN in WebKit::WebSpeechRecognitionHandle::operator WTF::PassRefPtr<WebCore::SpeechRecognition> | $1,000 | 2016-10-02 |
| 296276 | Heap-use-after-free in WebCore::SVGMatrixV8Internal::aAttributeSetterCallback | - | 2016-10-02 |
| 296268 | Heap-use-after-free in WebCore::accumulateDocumentTouchEventTargetRects | - | 2016-10-02 |
| 297718 | HTML generated by coping url in address bar should url-encode the url | - | 2016-10-02 |
| 296804 | Heap-use-after-free in webrtc::voe::Channel::SendRTCPPacket | - | 2016-10-02 |
| 295725 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGMatrix>::detachWrapper | - | 2016-10-02 |
| 295338 | ASSERTION FAILED: !object || object->isLayerModelObject(), UNKNOWN in WebKit::LinkHighlight::computeEnclosingCompositingLayer | - | 2016-10-02 |
| 295010 | Heap-use-after-free in WebCore::RenderObject::childAt | $2,000 | 2016-10-02 |
| 294687 | Heap-use-after-free in task_manager::ExtensionProcessResource::GetProfileName | - | 2016-10-02 |
| 294505 | ASSERTION FAILED: actualInfo->derefObjectFunction == info.derefObjectFunction, UNKNOWN in WebCore::V8IDBCursor::createWrapper | - | 2016-10-02 |
| 296003 | Heap-buffer-overflow in void std::__final_insertion_sort<WebCore::RenderTableCell**, bool | - | 2016-10-02 |
| 295695 | Security: Show javascript prompt over interstitial page | - | 2016-10-02 |
| 20450 | Chromium shouldn't allow XHR to local directories | - | 2016-10-02 |
| 20336 | Security: ensure proper escaping, filtering of user inputs in paths, login data for FTP | - | 2016-10-02 |
| 20931 | chrome.tabs.update should not allow navigation to javascript: URLs w/o permission | - | 2016-10-02 |
| 20318 | Security: do not auto-complete URLs with cloaked credentials | - | 2016-10-02 |
| 19505 | Mixed content flash not causing mixed content warnings | - | 2016-10-02 |
| 19340 | Themes from URLs without the ".crx" file extension install without prompt | - | 2016-10-02 |
| 19334 | test | - | 2016-10-02 |
| 19316 | Security: download shelf question for themes from untrusted locations is not honest | - | 2016-10-02 |
| 19212 | Security: script injection possible in JSON.parse; will lead to XSS in some web apps | - | 2016-10-02 |
| 19158 | libxml2 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3529 | - | 2016-10-02 |
| 20334 | Security: restrict IPs, ports for PASV ftp mode | - | 2016-10-02 |
| 20233 | Crash potentially due to resource exhaustion | - | 2016-10-02 |
| 18682 | Extensions privileges granted to process that calls window.open | - | 2016-10-02 |
| 18672 | yuv_row_linux.cc clip() DCHECK too conservative? | - | 2016-10-02 |
| 18639 | Crash [@ 0xffffffff] | - | 2016-10-02 |
| 18009 | Security: Investigate NTLM reflection vulnerability | - | 2016-10-02 |
| 17655 | Security: Bypass pop-up blocker using javascript: url in a pop-up. | - | 2016-10-02 |
| 16535 | Security: terminate busy loops on page transitions | - | 2016-10-02 |
| 16413 | Security: Redirected XHR includes custom headers, CSRF risk | - | 2016-10-02 |
| 18803 | Avast can't scan all files of chrome's cache: password protected | - | 2016-10-02 |
| 15701 | XSS issue due to the lack of support for ISO-2022-KR | - | 2016-10-02 |
| 15556 | innerHTML applies meta/link/title tags before getting commited. | - | 2016-10-02 |
| 14508 | Security: browser crash with memmove() memory corruption upon large chunked encoding chunk size | - | 2016-10-02 |
| 14211 | Reproducible browser crash when quickly scrolling wide page horizontally | - | 2016-10-02 |
| 13997 | Clicking an external link in an extension page shouldn't reuse the same process. | - | 2016-10-02 |
| 15766 | Security: focus() selective keystroke redirection | - | 2016-10-02 |
| 14719 | Security: possible memory corruption in v8 regex execution engine | - | 2016-10-02 |
| 12617 | Starting a hiden download can allow attacker to determine how long the browser stays open. | - | 2016-10-02 |
| 12523 | Crash - Menu::RunMenuAt(int,int) | - | 2016-10-02 |
| 12307 | Subtle mixed content bugs | - | 2016-10-02 |
| 12303 | Chrome falls back to DIRECT connections once all proxies have failed. | - | 2016-10-02 |
| 12810 | Renderer can crash browser through OOM using document.title | - | 2016-10-02 |
| 13029 | NIL | - | 2016-10-02 |
| 12591 | Popup blocker bypass/open webpage in default browser using WMP Active-X | - | 2016-10-02 |
| 11776 | Security: Linux Chromium config directory is world/group-readable, including cookies | - | 2016-10-02 |
| 11739 | V8Proxy::ToNativeObjectImpl ASSERT(MaybeDOMWrapper(object)); | - | 2016-10-02 |
| 11545 | Extensions can be loaded by web content | - | 2016-10-02 |
| 11308 | ReadAV [ARBITRARY]@chrome!NPAPI::PluginInstance::NPP_DestroyStream+0x111 | - | 2016-10-02 |
| 11205 | CoInitialize called in renderer (before sandbox lockdown) | - | 2016-10-02 |
| 11178 | New Layout test failures for WebKit merge 42932:42994 | - | 2016-10-02 |
| 12142 | Crash when proxy responds to CONNECT request with Content-Length: 0 | - | 2016-10-02 |
| 11934 | Crash: Alert box in event listeners | - | 2016-10-02 |
| 9760 | pasting "( ĂŻÂœÂ„ĂÂĂŻÂœÂ„)ĂŻÂŸÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂĂąÂÂ@ ĂŻÂœÂŒĂŻÂœÂźĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂŸÂĂŻÂœÂ°ĂŻÂœÂ°ĂŻÂœÂ°ĂŻÂŸÂ" to address bar causes full crash | - | 2016-10-02 |
| 9860 | ChromeHTML URI handler vulnerability | - | 2016-10-02 |
| 10957 | UXSS sharing window.external among frames | - | 2016-10-02 |
| 10869 | Buffer overflow in browser process while de-serializing SkBitmap (heap overwrite) | - | 2016-10-02 |
| 10736 | SkMask::computeImageSize() integer overflow | - | 2016-10-02 |
| 9877 | Security: cross domain thefts via CSS string property injection | - | 2016-10-02 |
| 10996 | Security: job object based restrictions no longer seem to be enforced | - | 2016-10-02 |
| 9303 | Security: possible use-after-free in OpenTypeUtilities.cpp | - | 2016-10-02 |
| 9608 | An HTTP response with code 401 and header with name="WWW-Authenticate" value="" crashes browser | - | 2016-10-02 |
| 9019 | zdi-can-464: malformed svglist parsing code execution | - | 2016-10-02 |
| 8757 | Cross-origin XMLHttpRequest is always allowed | - | 2016-10-02 |
| 8706 | Mixed content warning can be removed | - | 2016-10-02 |
| 8473 | Fix CONNECT requests with user-cancelled auth | - | 2016-10-02 |
| 8198 | Need to upgrade ICU in third_party | - | 2016-10-02 |
| 319117 | Master bug for Mobile Pwn2Own 2013 exploit from Pinkie Pie | - | 2016-10-02 |
| 319040 | Heap-buffer-overflow in WebCore::Element::pseudoStyleCacheIsInvalid | - | 2016-10-02 |
| 318791 | Security: Crash in aura::Window::NotifyWindowHierarchyChangeAtReceiver | - | 2016-10-02 |
| 319125 | Security: ClipboardHostMsg_WriteObjectsAsync allows to escape the sandbox | - | 2016-10-02 |
| 317999 | Security: Integer overflow leading to exploitable buffer overflow on 32-bit when parsing encrypted mp4 | - | 2016-10-02 |
| 317284 | ASSERTION FAILED: width == frameRect.width(), UNKNOWN in WebCore::WEBPImageDecoder::applyPostProcessing | - | 2016-10-02 |
| 317819 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlockFlow::createLineBoxes | - | 2016-10-02 |
| 317734 | Disabling filters over IPC for M32 | - | 2016-10-02 |
| 317485 | Use-after-free from SVGMatrixTearOff | - | 2016-10-02 |
| 317423 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
| 317286 | Stack-buffer-overflow in content::MakeWebMouseWheelEvent | - | 2016-10-02 |
| 318577 | Heap-use-after-free in WebCore::V8SVGTransform::resolveWrapperReachability | - | 2016-10-02 |
| 317913 | Heap-use-after-free in ChromeDownloadManagerDelegate::OnDownloadTargetDetermined | - | 2016-10-02 |
| 315889 | Security: ASAN heap-use-after-free in AnimationController::endAnimationUpdate | $3,000 | 2016-10-02 |
| 317210 | Heap-use-after-free in WebCore::RenderText::firstAbstractInlineTextBox | - | 2016-10-02 |
| 317097 | ASSERTION FAILED: m_context->document().documentElement() != m_context, Heap-use-after-free in WebCore::SVGTransformV8Internal::angleAttributeGetterCallback | - | 2016-10-02 |
| 316697 | Missing Skia cls for M32 to complete safe SVG communication over IPC | - | 2016-10-02 |
| 316339 | Heap-buffer-overflow in sk_getMetrics_glyph_00 | - | 2016-10-02 |
| 316298 | Security: Bad cast in ToRenderWidgetHostViewAura in web_contents_view_aura.cc | - | 2016-10-02 |
| 316032 | HPKP Pin-Sets set over headers are appended without a uniqueness check | - | 2016-10-02 |
| 317173 | CHECK failure in CHECK(p->IsSmi()) failed: ../../v8/src/objects-debug.cc(59) | - | 2016-10-02 |
| 317211 | Heap-buffer-overflow in PL_strdup | - | 2016-10-02 |
| 317174 | Heap-buffer-overflow in PORT_Alloc_Util | - | 2016-10-02 |
| 314469 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::doApply | $2,000 | 2016-10-02 |
| 314402 | UNKNOWN in WebCore::computeShapePaddingBounds | - | 2016-10-02 |
| 314225 | Heap-buffer-overflow in Null_Cipher | - | 2016-10-02 |
| 315842 | Heap-use-after-free in WebCore::HTMLTreeBuilder::adjustedCurrentStackItem | $2,000 | 2016-10-02 |
| 313939 | Security: Cross-origin information disclosure through createMediaElementSource and OfflineAudioContext | $4,000 | 2016-10-02 |
| 313743 | Heap-use-after-free in extensions::ExtensionAPI::SplitDependencyName | - | 2016-10-02 |
| 313529 | Heap-use-after-free in WebCore::Node::containsIncludingShadowDOM | - | 2016-10-02 |
| 313435 | Security: Prerendered pages can add incorrect alias URLs and intercept future navigations to them | - | 2016-10-02 |
| 313399 | Security: backport ARM uaccess fix | - | 2016-10-02 |
| 313005 | Heap-use-after-free in WebCore::Element::focus | - | 2016-10-02 |
| 312689 | ChromeĂąÂÂs HSTS preloads and certificate pinning does not work for wildcard-based domains when you input a ĂąÂÂ-.ù before the actual domain name. (e.g. https://abc.def-.drive.google.com) | - | 2016-10-02 |
| 312639 | ASSERTION FAILED: !m_history, Heap-use-after-free in WebCore::Document::nodeChildrenWillBeRemoved | - | 2016-10-02 |
| 314088 | Use-after-free in content::WebPluginDelegateStub::~WebPluginDelegateStub | - | 2016-10-02 |
| 312210 | "Require password to wake from sleep" option does not take effect | - | 2016-10-02 |
| 312250 | Security: Access after the end of the buffer due to undefined behavior in Pickle::FindNext | - | 2016-10-02 |
| 312046 | Heap-use-after-free in content::RenderViewHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
| 312028 | Heap-use-after-free in WebCore::SharedStyleFinder::canShareStyleWithElement | - | 2016-10-02 |
| 312016 | ViewHostMsg_CreateWindow: next route_id can be taken from the wrong process | - | 2016-10-02 |
| 311909 | Heap-use-after-free in WebCore::RenderTextFragment::originalText | - | 2016-10-02 |
| 311908 | ASSERTION FAILED: !needsSectionRecalc(), Heap-use-after-free in WebCore::RenderTable::topNonEmptySection | - | 2016-10-02 |
| 311548 | Security: inline svg that has not been marked as laid out causes ASSERT_WITH_SECURITY_IMPLICATION | - | 2016-10-02 |
| 312050 | UNKNOWN in WebCore::CanvasRenderingContext2D::drawTextInternal | - | 2016-10-02 |
| 311036 | strongswan: CVE-2013-6075 | - | 2016-10-02 |
| 310259 | ASSERTION FAILED: width == frameRect.width(), UNKNOWN in WebCore::WEBPImageDecoder::applyPostProcessing | - | 2016-10-02 |
| 311040 | strongswan: CVE-2013-6076 | - | 2016-10-02 |
| 310257 | Heap-buffer-overflow in VP8LConvertFromBGRA | - | 2016-10-02 |
| 310794 | Security: Blocking of HTTP iframes in HTTPS pages can be circumvented by using data: urls | - | 2016-10-02 |
| 7986 | REGRESSION: file:// URLs can script web URLs | - | 2016-10-02 |
| 7713 | Unescape according to the safe browsing spec | - | 2016-10-02 |
| 7338 | 30x redirects silently honored in response to CONNECT | - | 2016-10-02 |
| 7214 | Cross-domain access to stylesheet text should not be allowed | - | 2016-10-02 |
| 6869 | SVG support is crashy in 2.0.157.2 | - | 2016-10-02 |
| 6264 | Security bug: something very wrong with same-origin checks | - | 2016-10-02 |
| 6062 | Chrome: Crash Report - Stack Signature: WebCore::GIFImageDecoder::haveDecodedRow | - | 2016-10-02 |
| 7590 | Rogue renderer can tamper with Windows. | - | 2016-10-02 |
| 5825 | chromehtml: Elevate on Vista if no permission to modify key | - | 2016-10-02 |
| 5596 | Bookmarklets clicked on new tab page execute in chrome-resource security context | - | 2016-10-02 |
| 5271 | Add a test for bug 2074 | - | 2016-10-02 |
| 5248 | cross-frame-access-protocol*.html layout tests are failing | - | 2016-10-02 |
| 5247 | Cross-frame-access-*-explicit-domain layout tests failing | - | 2016-10-02 |
| 4943 | Rogue renderer could crash other renderers / browser via stats table. | - | 2016-10-02 |
| 4772 | Stateless key event handling from renderer to browser | - | 2016-10-02 |
| 4197 | Further restrict access of file URL | - | 2016-10-02 |
| 4150 | Security: SwissSign Root marked for EV | - | 2016-10-02 |
| 3896 | Make tests for bug 2074 fix and contribute to webkit | - | 2016-10-02 |
| 3851 | Security: need backport of WebKit bug for v1.0 release | - | 2016-10-02 |
| 3823 | Security: Empty string between ISO-2022 escape sequences can be potentially exploited. Make sure we don't suffer | - | 2016-10-02 |
| 3645 | Security: intermittent NULL ptr crash when browser close attempted with a non-responsive tab | - | 2016-10-02 |
| 4387 | Security: Microsoft "feature" causes dates > December 31st 3000 to crash renderer crash | - | 2016-10-02 |
| 3538 | SSL CN mismatch not triggering warning | - | 2016-10-02 |
| 3431 | Drag & drop javascript link to Windows desktop | - | 2016-10-02 |
| 3275 | Security: Popup-blocker bypass using click event | - | 2016-10-02 |
| 3256 | Security: block windows / prompts, or disable scripting altogether, while security interstitials are displayed | - | 2016-10-02 |
| 3628 | Websites can spawn infinite external protocol handler popups. | - | 2016-10-02 |
| 3382 | V8 crashes on lots of popups. | - | 2016-10-02 |
| 2759 | A range of non-characters (U+FDD0 .. U+FDEF) are passed through in IsStringUTF8 | - | 2016-10-02 |
| 2966 | Chrome Window.open & alert DoS | - | 2016-10-02 |
| 2618 | Web Inspector should not rely on the untrusted page to implement escapeHTML | - | 2016-10-02 |
| 2579 | tab_strip_model.cc can Crash Chrome.dll | - | 2016-10-02 |
| 2316 | Chromium automatically continues the request for a sub-resource with a certificate error under some conditions. | - | 2016-10-02 |
| 2748 | Crash when doing a view-source on a https-link with invalid security certificate | - | 2016-10-02 |
| 2957 | Clicking "Safe Browsing diagnostic page" link broken on malware interstitial | - | 2016-10-02 |
| 2632 | Advisory: Google Chrome Carriage Return Null Object Memory Exhaustion Remote Dos | - | 2016-10-02 |
| 1488 | Google Chrome Browser Exploit | - | 2016-10-02 |
| 1414 | Chrome Buffer Overlow Vulnerability - "SaveAs" Function | - | 2016-10-02 |
| 1980 | Content-Disposition triggers buffer overflow | - | 2016-10-02 |
| 2074 | DBCS invalid multi-byte over-consumption leads to XSS vectors | - | 2016-10-02 |
| 1967 | Append .download to downloaded DLL files | - | 2016-10-02 |
| 1227 | Firedragging "polished" - drag an executable file to the desktop appearing to be an image | - | 2016-10-02 |
| 1208 | Never elide file extensions (at least in download UI) | - | 2016-10-02 |
| 1210 | Don't trigger buttons on second click of a double-click | - | 2016-10-02 |
| 213 | Denial of Service | - | 2016-10-02 |
| 100 | custom cursor icon rendered incorrectly | - | 2016-10-02 |
| 326229 | Heap-buffer-overflow in SkBicubicImageFilter::onFilterImage | - | 2016-10-02 |
| 326187 | UNKNOWN in SkMagnifierImageFilter::onFilterImage | - | 2016-10-02 |
| 326199 | Heap-buffer-overflow in SkBitmap::copyTo | - | 2016-10-02 |
| 325624 | ASSERTION FAILED: !object || (object->isRenderBlockFlow()), UNKNOWN in WebCore::toRenderBlockFlow | - | 2016-10-02 |
| 326195 | Heap-buffer-overflow in SkSrcXfermode::xfer32 | - | 2016-10-02 |
| 326206 | Heap-buffer-overflow in SkDilateX_SSE2 | - | 2016-10-02 |
| 326197 | Heap-buffer-overflow in SkDiffuseLightingImageFilter::onFilterImage | - | 2016-10-02 |
| 326198 | Heap-buffer-overflow in Clamp_S32_D32_nofilter_trans_shaderproc | - | 2016-10-02 |
| 326118 | Security: chrome: address bar spoofing in Chrome for iOS | - | 2016-10-02 |
| 324815 | Apps can be installed from outside CWS and from non-secure sites | - | 2016-10-02 |
| 324812 | Security: leaking the raw global object when passing callbacks between contexts | - | 2016-10-02 |
| 325071 | Use-after-free in content::WebGraphicsContext3DCommandBufferImpl::InitializeCommandBuffer | - | 2016-10-02 |
| 324969 | Security: Address bar spoofing in Chrome for Android | $1,000 | 2016-10-02 |
| 325225 | Crash on keyed load invocation | - | 2016-10-02 |
| 324817 | Security: Unprompted app installation allowed | - | 2016-10-02 |
| 324321 | Heap-use-after-free in WebCore::Document::updateLayout | - | 2016-10-02 |
| 324320 | ASSERTION FAILED: !tryCatch.HasCaught() || result.IsEmpty(), Heap-use-after-free in content::RenderViewHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
| 324323 | ASSERTION FAILED: iteration >= 0, Heap-buffer-overflow in WebCore::KeyframeAnimationEffect::PropertySpecificKeyframeGroup::sample | - | 2016-10-02 |
| 324324 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::removeRedundantStylesAndKeepStyleSpanInline | - | 2016-10-02 |
| 324530 | Heap-use-after-free in WebCore::DocumentMarkerController::removeMarkersFromList | - | 2016-10-02 |
| 322965 | In-page search form steals focus/navigation control from Chrome's URL bar | - | 2016-10-02 |
| 323969 | Attempting free in std::_Rb_tree<blink::WebFrame*, std::pair<blink::WebFrame* const, content::RenderFrameImpl*>, std::_ | - | 2016-10-02 |
| 323682 | Use-after-free in WebCore::SVGAnimatedProperty::detachAnimatedPropertiesForElement | - | 2016-10-02 |
| 323595 | Heap-buffer-overflow in SkValidatingReadBuffer::getArrayCount | - | 2016-10-02 |
| 322662 | Multiprofile: Screen does not lock when non-corp account is active | - | 2016-10-02 |
| 322891 | Heap-use-after-free in WebCore::RenderLayerScrollableArea::updateCompositingLayersAfterScroll | $2,000 | 2016-10-02 |
| 322554 | Heap-use-after-free in WebCore::MediaStreamAudioSourceNode::process | - | 2016-10-02 |
| 322527 | Incognito cookies make their way into non-incognito cookie space when using HTTPS Everywhere extension | - | 2016-10-02 |
| 322959 | URL Spoof Vulnerability | $500 | 2016-10-02 |
| 322937 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
| 322575 | ASSERTION FAILED: activeDuration >= 0, Heap-buffer-overflow in WebCore::KeyframeAnimationEffect::PropertySpecificKeyframeGroup::sample | - | 2016-10-02 |
| 321831 | UNKNOWN in SkProcCoeffXfermode::CreateProc | - | 2016-10-02 |
| 322195 | Heap-use-after-free in content::WebRTCIdentityServiceHost::OnRequestIdentity | - | 2016-10-02 |
| 321783 | dev-libs/nspr needs upgrade from upstream portage | - | 2016-10-02 |
| 321781 | dev-libs/nss needs upgrade from upstream portage | - | 2016-10-02 |
| 322348 | Heap-use-after-free in WebCore::Element::focus | - | 2016-10-02 |
| 321802 | Heap-buffer-overflow in SkValidatingReadBuffer::readPoint | - | 2016-10-02 |
| 321790 | UNKNOWN in SkValidatingReadBuffer::readString | - | 2016-10-02 |
| 321940 | Security: Inserting a Google account to Chrome and stealing user's private data | $5,000 | 2016-10-02 |
| 320762 | Heap-use-after-free in WebCore::SVGStringListV8Internal::clearMethodCallback | - | 2016-10-02 |
| 321037 | Heap-use-after-free in WebCore::V8SVGStringList::resolveWrapperReachability | $500 | 2016-10-02 |
| 321495 | Heap-use-after-free in WebCore::StyleSheetCollection::resetAllRuleSetsInTreeScope | - | 2016-10-02 |
| 320796 | Content-security-policy object-src: isn't applied against <param name="source"> | - | 2016-10-02 |
| 320239 | CHECK failure in CHECK failed: it != streams_.end() in media_stream_dispatcher_host.cc(242) | - | 2016-10-02 |
| 320344 | Heap-use-after-free in WebCore::ChannelProvider::provideInput | $500 | 2016-10-02 |
| 319860 | OOB read in V8 | - | 2016-10-02 |
| 319835 | OOB write in V8 (only 64bit) | - | 2016-10-02 |
| 319722 | Heap-buffer-overflow in v8::internal::ExternalByteArray::SetValue | - | 2016-10-02 |
| 319477 | clipboard.cc issues | - | 2016-10-02 |
| 320314 | Heap-use-after-free in autofill::PasswordAutofillAgent::DidStartProvisionalLoad | - | 2016-10-02 |
| 320313 | Heap-use-after-free in base::internal::Invoker<1, base::internal::BindState<base::internal::RunnableAdapter<void | - | 2016-10-02 |
| 319914 | Use-after-free in v8::internal::GlobalHandles::Destroy | - | 2016-10-02 |
| 331571 | Typing pandora.com in omnibox automatically redirects user to native app, if installed | - | 2016-10-02 |
| 331444 | [LangFuzz] Crash at v8::internal::StoreBuffer::Compact with invalid write | $3,000 | 2016-10-02 |
| 331416 | [LangFuzz] Crash on Heap with Array access/length and invalid read | $3,000 | 2016-10-02 |
| 331725 | Security: body of POST request initiated 302-redirect chain can be recovered by script on last page in chain using XSS Auditor | $500 | 2016-10-02 |
| 331790 | Security: use-after-free in content::WebContentsImpl::~WebContentsImpl | $1,000 | 2016-10-02 |
| 331253 | Use-after-free in v8::HandleScope::HandleScope | - | 2016-10-02 |
| 331389 | Heap-use-after-free in er_supported | - | 2016-10-02 |
| 331219 | Using a long JavaScript alert() string can hide buttons and prevention checkbox | - | 2016-10-02 |
| 331168 | Security: scrollbar-corner can be drawn outside the containing frame, allowing redress of parent frame. | $500 | 2016-10-02 |
| 331060 | Security: XSS Auditor behavior can cause leak of submitted form data because of about:blank redirection | $1,000 | 2016-10-02 |
| 331254 | Heap-buffer-overflow in WebCore::BisonCSSParser::parseValue | - | 2016-10-02 |
| 331232 | Use-after-free in WebCore::Editor::rangeOfString | - | 2016-10-02 |
| 330710 | UXSS can be performed because XSS Auditor processes tokens inside script tag separately | - | 2016-10-02 |
| 330660 | use-after-free in SpeechRecognitionBubbleView::GetAnchorRect | $500 | 2016-10-02 |
| 330626 | Heap-use-after-free in WebCore::RenderInline::willBeDestroyed | $2,000 | 2016-10-02 |
| 330750 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlockFlow::createLineBoxes | - | 2016-10-02 |
| 330663 | UXSS from a local MHTML file | $1,000 | 2016-10-02 |
| 330222 | UNKNOWN in TIntermSymbol::TIntermSymbol | - | 2016-10-02 |
| 330420 | ASSERTION FAILED: m_stateStack.size() == 1, Heap-use-after-free in WebCore::ScrollView::paint | $1,000 | 2016-10-02 |
| 329978 | AutofillHostMsg_ShowPasswordSuggestions: validate that suggestions.size() == realms.size() | - | 2016-10-02 |
| 330293 | UNKNOWN in SkRegion::setPath | $3,000 | 2016-10-02 |
| 329723 | Security: arbitrary memory read in logging::LogMessage::Init | - | 2016-10-02 |
| 329258 | Global-buffer-overflow in BrotliHuffmanTreeBuildImplicit | - | 2016-10-02 |
| 329547 | Heap-buffer-overflow in ReadHuffmanCode | - | 2016-10-02 |
| 329006 | ASSERTION FAILED: std::isfinite(num), Heap-buffer-overflow in SkChopCubicAt | - | 2016-10-02 |
| 329651 | UAF: Utterance should not keep a raw pointer to TtsMessageFilter | - | 2016-10-02 |
| 329254 | Global-buffer-overflow in SkMallocPixelRef::SkMallocPixelRef | - | 2016-10-02 |
| 329386 | Security: Handling HSTS headers effectively clobbers preloaded pins | - | 2016-10-02 |
| 329238 | Heap-use-after-free in WebCore::RenderBlockFlow::computeBlockDirectionPositionsForLine | - | 2016-10-02 |
| 328202 | Security: v8: invalid overflow checks in Zone::NewExpand() | - | 2016-10-02 |
| 328231 | Security: incorrect overflow check in SparseControl::StartIO() | - | 2016-10-02 |
| 328456 | ASSERTION FAILED: !m_deletionHasBegun, UNKNOWN in WebCore::FormAssociatedElement::formRemovedFromTree | - | 2016-10-02 |
| 328620 | The GPU sandbox sometimes call InitializeSandbox() with threads appearing running. | - | 2016-10-02 |
| 328203 | Security: WebGLRenderingContext::copyTexSubImage2D - invalid checks for overflow. | - | 2016-10-02 |
| 327824 | The seccomp-bpf sandbox fails silently on the GPU process with threads | - | 2016-10-02 |
| 327372 | Heap-buffer-overflow in SkDisplacementMapEffect::onFilterImage | - | 2016-10-02 |
| 327729 | Heap-use-after-free in WebCore::SVGPropertyTearOff<WebCore::SVGMatrix>::detachWrapper | - | 2016-10-02 |
| 327720 | Heap-use-after-free in chrome_browser_net::GetDataReductionRequestType | - | 2016-10-02 |
| 327626 | Security: RELEASE_ASSERT in SubtreeLayoutScope destructor | - | 2016-10-02 |
| 326860 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
| 326854 | Heap-use-after-free in WebCore::FormAssociatedElement::formRemovedFromTree | $1,000 | 2016-10-02 |
| 327065 | Heap-use-after-free in StyleResolver::applyMatchedProperties | - | 2016-10-02 |
| 327070 | ASSERTION FAILED: !m_hasBadParent, Heap-use-after-free in WebCore::InlineBox::nextLeafChild | - | 2016-10-02 |
| 339610 | Heap-use-after-free in WebCore::Canvas2DLayerBridge::freeReleasedMailbox | - | 2016-10-02 |
| 339498 | Heap-use-after-free in CacheCreator::DoCallback | - | 2016-10-02 |
| 339337 | Use RefPtr in PageWidgetDelegate and guard RenderView | - | 2016-10-02 |
| 339314 | Heap-use-after-free in content::VideoCaptureController::DoIncomingCapturedI420BufferOnIOThread | - | 2016-10-02 |
| 338532 | UNKNOWN in /usr/lib/x86_64-linux-gnu/libstdc++.so.6+0x6441f | - | 2016-10-02 |
| 338524 | Security: TOCTOU Bug in Windows Sandbox Handle Duplication Service | - | 2016-10-02 |
| 338561 | Heap-use-after-free in content::MediaStreamManager::FinalizeEnumerateDevices | - | 2016-10-02 |
| 338393 | Heap-use-after-free in content::GpuChannelHost::Send | - | 2016-10-02 |
| 338354 | Heap-use-after-free in IPC::Message::Header const* Pickle::headerT<IPC::Message::Header> | - | 2016-10-02 |
| 338345 | Heap-use-after-free in content::WebContentsImpl::CreateNewWindow | - | 2016-10-02 |
| 338538 | Security: Windows Sandbox Anonymous Kernel Object Unrestricted DACL | $3,000 | 2016-10-02 |
| 338464 | UaF of ColorChooserAura | - | 2016-10-02 |
| 338164 | Heap-use-after-free in std::_Rb_tree<std::string, std::pair<std::string const, extensions::ExtensionDownloaderDelegate::Pin | - | 2016-10-02 |
| 338109 | ASSERTION FAILED: !box || (box->isSVGInlineFlowBox()), UNKNOWN in WebCore::SVGRootInlineBox::layoutCharactersInTextBoxes | - | 2016-10-02 |
| 337882 | Security: ASAN "heap-buffer-overflow" in CallBitmapXferProc | $2,000 | 2016-10-02 |
| 338341 | Heap-use-after-free in content::RenderProcessHostImpl::ProcessDied | - | 2016-10-02 |
| 338124 | Heap-use-after-free in elapsed | - | 2016-10-02 |
| 337572 | Heap-use-after-free in cricket::BaseChannel::SendPacket | - | 2016-10-02 |
| 337561 | ASSERTION FAILED: controller->hasClientForTest(), Heap-buffer-overflow in WebCore::GeolocationClientMock::setPositionUnavailableError | - | 2016-10-02 |
| 337488 | Security: Even when there are certificate errors, password auto-fill (easy-fill) works | - | 2016-10-02 |
| 337428 | Tracking bug for internal security fixes for Chrome 32, Release 1 | - | 2016-10-02 |
| 337071 | UNKNOWN in NetworkASync::QueueDeletion | - | 2016-10-02 |
| 337727 | Heap-buffer-overflow in __gnu_cxx::new_allocator<unsigned long>::construct | - | 2016-10-02 |
| 337746 | Security: unicode character can create phishing-friendly address bar | $1,500 | 2016-10-02 |
| 337562 | Heap-use-after-free in WebCore::HTMLFormElement::removeImgElement | - | 2016-10-02 |
| 336436 | Heap-use-after-free in WebCore::V8SVGAnimatedRect::visitDOMWrapper | - | 2016-10-02 |
| 336875 | Heap-use-after-free in cc::FrameRateController::DidSwapBuffersComplete | - | 2016-10-02 |
| 336841 | Security: WebRequest API allows modifying details in inline extension installations | - | 2016-10-02 |
| 335416 | Heap-buffer-overflow in WebCore::Font::expansionOpportunityCount | - | 2016-10-02 |
| 335242 | Heap-buffer-overflow in setup_frame_size_with_refs | - | 2016-10-02 |
| 335921 | Heap-use-after-free in WebCore::AutofocusTask::performTask | - | 2016-10-02 |
| 334448 | Uninit memory access in CLD2 inside translate::DeterminePageLanguage | - | 2016-10-02 |
| 334314 | IndexedDB: Replace passing identically-sized vectors through IPC with passing pairs/tuples | - | 2016-10-02 |
| 334897 | Security: Windows Sandbox Named Pipe Policy Doesn't Block Relative Paths | $2,000 | 2016-10-02 |
| 334204 | Same-origin security issue in <video> on Android | - | 2016-10-02 |
| 334082 | Heap-use-after-free in plugins::PluginPlaceholder::ReplacePlugin | - | 2016-10-02 |
| 333885 | Stack-use-after-return in _mesa_optimize_program | - | 2016-10-02 |
| 334725 | Heap-use-after-free in WebCore::SpaceSplitString::set | - | 2016-10-02 |
| 334274 | Security: Sandbox escape due to vector length mismatch in IndexedDBHostMsg_DatabasePut IPC message | - | 2016-10-02 |
| 333378 | Heap-use-after-free in WebCore::ResourceFetcher::frame() | $1,000 | 2016-10-02 |
| 333156 | Use-after-free in WebCore::SVGAnimatedProperty::detachAnimatedPropertiesForElement | - | 2016-10-02 |
| 333155 | Bad cast to XPath::Filter in XPathGrammar.y | - | 2016-10-02 |
| 333094 | Security: Flash allows clipboard theft / manipulation for duration of session after receiving a single paste event | - | 2016-10-02 |
| 333058 | Security: set_state global_handles renderer crash (UAF) with Web Workers and Web SQL | $1,000 | 2016-10-02 |
| 333038 | Security: Sandbox escape due to vector length mismatch in ImageHostMsg_DidDownloadImage IPC message | - | 2016-10-02 |
| 333036 | Tracking bug for internal security fixes for Chrome 32, Release 0 | - | 2016-10-02 |
| 333431 | ASSERTION FAILED: !node || (node->isSVGElement()), UNKNOWN in WebCore::SVGSMILElement::connectEventBaseConditions | - | 2016-10-02 |
| 332677 | ASSERTION FAILED: !node || (node->isElementNode()), UNKNOWN in WebCore::toElement | - | 2016-10-02 |
| 332579 | Drag-and-drop files not working on Windows Aura | - | 2016-10-02 |
| 332957 | PartialCircularBuffer is unsafe to use across security boundaries | - | 2016-10-02 |
| 332675 | Use-after-free in plugins::PluginPlaceholder::UpdateMessage | - | 2016-10-02 |
| 345526 | UNKNOWN in v8::internal::FixedArrayBase::length | - | 2016-10-02 |
| 345715 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
| 344674 | UNKNOWN in content::TouchDispositionGestureFilter::OnGestureEventPacket | - | 2016-10-02 |
| 344654 | Use-after-free in net::URLRequestContextGetter::OnDestruct | - | 2016-10-02 |
| 345014 | Wild-access in WebCore::V8PerContextDataHolder::from | - | 2016-10-02 |
| 344881 | Heap-use-after-free in WebCore::SpeechSynthesis::cancel | $4,000 | 2016-10-02 |
| 344359 | ASSERTION FAILED: bounds.width() >= 0 && bounds.height() >= 0 && radii.width() >= 0 && radii.height() >= 0, Heap-use-after-free in WebCore::RenderBlockFlow::constructLine | - | 2016-10-02 |
| 344265 | Heap-use-after-free in views::TooltipManagerAura::UpdateTooltip | - | 2016-10-02 |
| 344186 | OOB write due to invalid bounds check in v8 | - | 2016-10-02 |
| 344051 | Security: dump_vpd_log can be tricked into creating a file (or corrupt non-regular file) | - | 2016-10-02 |
| 344492 | Heap-use-after-free in WebCore::SVGImage::setContainerSize | $1,000 | 2016-10-02 |
| 344360 | ASSERTION FAILED: !node || (node->isElementNode()), UNKNOWN in WebCore::RenderBlock::clone | - | 2016-10-02 |
| 344230 | Use-after-free in WebCore::RootInlineBox::closestLeafChildForPoint | $1,000 | 2016-10-02 |
| 343648 | Stack-buffer-overflow in content::DecodeAudioFileData | - | 2016-10-02 |
| 343582 | Use-after-free in WebCore::DocumentTimeline::createPlayer | - | 2016-10-02 |
| 343383 | Renderer crash / heap-use-after-free in BrowserPlugin | - | 2016-10-02 |
| 343265 | Heap-use-after-free in content::NavigatorImpl::NavigateToEntry | - | 2016-10-02 |
| 343928 | UNKNOWN in v8::internal::FixedArrayBase::length | - | 2016-10-02 |
| 343964 | UNKNOWN in v8::internal::FixedArray::get | - | 2016-10-02 |
| 343461 | Global-buffer-overflow in SkBitmap::setConfig | - | 2016-10-02 |
| 343661 | Security: UAF while deleting IndexedDB databases from (shared) workers | $3,000 | 2016-10-02 |
| 342618 | Security: UXSS via dispatchEvent on iframes (subject to some conditions) | $3,000 | 2016-10-02 |
| 342735 | Security: UaF in controller of color chooser | $1,000 | 2016-10-02 |
| 342949 | Security: Bypass extension install prompt with --install-from-webstore and --force-app-mode | - | 2016-10-02 |
| 343050 | Use-after-free in WebCore::FrameView::autoSizeIfEnabled | - | 2016-10-02 |
| 342856 | UNKNOWN in WebCore::ThreadState::visitStack | - | 2016-10-02 |
| 341865 | Heap-use-after-free in WebCore::FrameLoader::loadHistoryItem | - | 2016-10-02 |
| 342151 | Heap-use-after-free in ui::OnFileNotSelected | - | 2016-10-02 |
| 341093 | Heap-use-after-free in WebCore::GraphicsContext::restore | - | 2016-10-02 |
| 341220 | Chrome_ChromeOS: Crash Report - WebCore::KURL::init | - | 2016-10-02 |
| 340687 | Heap-use-after-free in WebCore::CompositedLayerMapping::~CompositedLayerMapping | - | 2016-10-02 |
| 340387 | Security: Unquoted path in mini_installer can lead to executing the wrong executable | - | 2016-10-02 |
| 340125 | CHECK failure in CHECK(is_valid) failed: ../../v8/src/v8conversions.h(107) | - | 2016-10-02 |
| 340124 | CHECK failure in CHECK(p->IsHeapObject()) failed: ../../v8/src/objects-debug.cc(219) | - | 2016-10-02 |
| 340697 | ASSERTION FAILED: m_match == Tag, Heap-buffer-overflow in WebCore::RuleSet::findBestRuleSetAndAdd | - | 2016-10-02 |
| 341754 | Heap-use-after-free in WebCore::WorkerThreadableWebSocketChannel::Peer::Peer | - | 2016-10-02 |
| 341555 | HTTP iFrame loaded into HTTPS page (Mixed active content protection bypass) | - | 2016-10-02 |
| 339994 | Heap-use-after-free in std::_Rb_tree<std::pair<int, media::AudioParameters>, std::pair<std::pair<int, media::AudioParameter | - | 2016-10-02 |
| 340001 | Heap-use-after-free in WebCore::CSSParserValueList::~CSSParserValueList | - | 2016-10-02 |
| 340007 | Heap-use-after-free in v8::internal::Heap::UpdateAllocationSiteFeedback | - | 2016-10-02 |
| 340048 | Heap-use-after-free in WebCore::V8SVGAnimatedString::visitDOMWrapper | - | 2016-10-02 |
| 339993 | ASSERTION FAILED: !box || (box->isSVGInlineFlowBox()), UNKNOWN in WebCore::SVGRootInlineBox::layoutCharactersInTextBoxes | - | 2016-10-02 |
| 339667 | Heap-use-after-free in content::BrowserMessageFilter::Send | - | 2016-10-02 |
| 351855 | Pwnium 4: Mali GPU driver does not mask out VM_MAYWRITE | - | 2016-10-02 |
| 351852 | AsyncPixelTransfersCompletedQuery does not validate shared memory offset | - | 2016-10-02 |
| 351811 | Security: Pwnium 4 GeoHot bug: cros-disks accepts labels, has path traversal issues. | - | 2016-10-02 |
| 351796 | Security: Pwnium 4 GeoHot bug: try_touch_experiment command injection | - | 2016-10-02 |
| 351788 | Security: Pwnium 4 GeoHot tracking bug | $150,000 | 2016-10-02 |
| 351787 | Pwnium 4: v8 OOB read/write with __defineGetter__ and bytesLength | - | 2016-10-02 |
| 351729 | Use-after-free in WebCore::RenderObject::setPreferredLogicalWidthsDirty | - | 2016-10-02 |
| 352043 | Chrome: Crash Report - WebCore::Resource::ResourceCallback::timerFired | - | 2016-10-02 |
| 351815 | Pwnium: Extension system allows compromised renderer access to crosh | - | 2016-10-02 |
| 351316 | Heap-use-after-free in WebCore::SMILTimeContainer::wakeupTimerFired | - | 2016-10-02 |
| 351504 | Heap-use-after-free in gfx::ImageSkia::operator= | - | 2016-10-02 |
| 351103 | sandbox::CodeGen::MergeTails (seccomp-bpf) is unsound for single-successor basic blocks | $500 | 2016-10-02 |
| 351314 | Heap-use-after-free in views::DesktopDispatcherClient::RunWithDispatcher | - | 2016-10-02 |
| 351320 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 351209 | UNKNOWN in v8::internal::MarkCompactCollector::ProcessMarkingDeque | - | 2016-10-02 |
| 350760 | Use-after-free in WebCore::ShadowTreeStyleSheetCollection::collectStyleSheets | - | 2016-10-02 |
| 350537 | Heap-use-after-free in printing::PrintViewManagerBase::ReleasePrinterQuery | - | 2016-10-02 |
| 350535 | Security: Callers of showModalDialog can be trivially XSSed by a cross-origin modal dialog | - | 2016-10-02 |
| 350863 | CHECK failure in CHECK(object->map()->IsMap()) failed: ../src/heap-inl.h(833) | - | 2016-10-02 |
| 350930 | Heap-use-after-free in std::_Rb_tree<std::pair<int, media::AudioParameters>, std::pair<std::pair<int, media::AudioParameter | - | 2016-10-02 |
| 350686 | Heap-use-after-free in webFrame | - | 2016-10-02 |
| 350509 | ASSERTION FAILED: !value || (value->isPrimitiveValue()), UNKNOWN in WebCore::StyleBuilder::applyProperty | - | 2016-10-02 |
| 350434 | [LangFuzz] Crash with jump to invalid address | $2,000 | 2016-10-02 |
| 350533 | Origin confusion bug in QUIC | - | 2016-10-02 |
| 350055 | Heap-use-after-free in WebCore::CSSParserValueList::~CSSParserValueList | - | 2016-10-02 |
| 349903 | ASSERTION FAILED: !object || (object->isListBox()), UNKNOWN in WebCore::HTMLSelectElement::listBoxDefaultEventHandler | $1,500 | 2016-10-02 |
| 349898 | Security: Integer Overflows in CharacterData::deleteData & CharacterData::replaceData | $1,500 | 2016-10-02 |
| 349465 | UNKNOWN in v8::internal::JSFunction::context | - | 2016-10-02 |
| 350518 | Security: WinSock initialized in Utility Process. | - | 2016-10-02 |
| 350100 | Heap-use-after-free in content::IndexedDBFactory::Open | - | 2016-10-02 |
| 349079 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
| 348952 | Insecure marked as secure when restored from session | - | 2016-10-02 |
| 348682 | ASSERTION FAILED: to <= m_run.length(), UNKNOWN in WebCore::HarfBuzzShaper::setDrawRange | - | 2016-10-02 |
| 348581 | Dynamically created script tags disregard Content-Type and X-Content-Type-Options | - | 2016-10-02 |
| 348550 | ParseHSTSHeader should tolerate trailing ";" | - | 2016-10-02 |
| 348333 | Security: base::SHA1HashBytes produces wrong SHA1 hash when |len| >= 4GB | - | 2016-10-02 |
| 348332 | Security: Integer overflow allocating shared memory in SoftwareFrameManager::SwapToNewFrame() | $3,000 | 2016-10-02 |
| 349135 | Heap-use-after-free in cc::internal::TaskGraphRunner::SetTaskGraph | - | 2016-10-02 |
| 348175 | Tracking bug for internal security fixes for Chrome 33, Release 1 | - | 2016-10-02 |
| 347909 | CHECK failure in CHECK(value->IsHeapObject()) failed: ../src/objects-debug.cc(295) | - | 2016-10-02 |
| 348319 | UNKNOWN in v8::internal::MemoryChunk::heap | - | 2016-10-02 |
| 347720 | Security: Protocol handler UI does not filter "protocol" and "title" strings | - | 2016-10-02 |
| 347543 | CHECK failure in CHECK(object_size <= Page::kMaxRegularHeapObjectSize) failed: ../src/ia32/macro-assembler-ia32.cc(15 | - | 2016-10-02 |
| 347532 | CHECK failure in CHECK(isolate->microtask_pending()) failed: ../src/execution.cc(358) | - | 2016-10-02 |
| 347528 | CHECK failure in CHECK(IsNativeContext()) failed: ../src/contexts.h(462) | - | 2016-10-02 |
| 347302 | Chrome_Linux: Crash Report - content::MediaStreamDispatcherHost::OnEnumerateDevices | - | 2016-10-02 |
| 347846 | Bypassing policies set by removing battery (can be fixed) | - | 2016-10-02 |
| 347284 | Scroll pointer iteration during tree sync is a really bad idea | - | 2016-10-02 |
| 347177 | Use-after-free in media::GpuVideoDecoder::Initialize | - | 2016-10-02 |
| 346997 | Security: Self signed assets don't fail. | - | 2016-10-02 |
| 346744 | Security: download attribute allows download without user interaction | - | 2016-10-02 |
| 346599 | Skia refcounted objects are held in non-refcounted places | - | 2016-10-02 |
| 346557 | Heap-use-after-free in autofill::PasswordGenerator::Generate | - | 2016-10-02 |
| 347262 | UNKNOWN in v8::internal::Map::instance_descriptors | - | 2016-10-02 |
| 346343 | NO STACK | - | 2016-10-02 |
| 346192 | Heap-use-after-free in WebCore::SVGFontFaceElement::associatedFontElement | $1,000 | 2016-10-02 |
| 346135 | Security: html files from file URLs can read data from other file URLs via drag-and-drop | $1,000 | 2016-10-02 |
| 346110 | Heap-use-after-free in get | - | 2016-10-02 |
| 346489 | Heap-buffer-overflow in VariablePacker::searchColumn | - | 2016-10-02 |
| 346141 | Global-buffer-overflow in GetVisitor | - | 2016-10-02 |
| 345820 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
| 345929 | mirrorv2 crashes when nobody is receiving | - | 2016-10-02 |
| 345959 | Integer overflows in StringBuilder | - | 2016-10-02 |
| 358254 | Heap-buffer-overflow in UDataMemory_normalizeDataPointer_46 | - | 2016-10-02 |
| 358059 | UNKNOWN in v8::internal::HeapObject::map_word | - | 2016-10-02 |
| 358057 | UNKNOWN in v8::internal::Simulator::DecodeType3 | - | 2016-10-02 |
| 358038 | Security: UAF/Crash in (websockets) onsentdata/reset with web and shared workers combined | $2,000 | 2016-10-02 |
| 357712 | Heap-use-after-free in void std::basic_string<unsigned short, base::string16_char_traits, std::allocator<unsigned short> >: | - | 2016-10-02 |
| 358471 | importScripts ignores script-src CSP | - | 2016-10-02 |
| 357382 | Security: ProcessManager::GetExtensionForRenderViewHost determines extension ID unsafely | - | 2016-10-02 |
| 357292 | Use-after-free in WebCore::GraphicsLayer::updateContentsRect | - | 2016-10-02 |
| 357669 | Heap-use-after-free in WebCore::FrameSelection::setSelection | - | 2016-10-02 |
| 357242 | Heap-use-after-free in WebCore::RenderBox::enclosingFloatPaintingLayer | - | 2016-10-02 |
| 357174 | Heap-use-after-free in WebCore::MemoryCache::insertInLRUList | - | 2016-10-02 |
| 357452 | Heap-use-after-free in WebCore::RenderTreeBuilder::createRendererForElementIfNeeded | - | 2016-10-02 |
| 357269 | Cross-origin request credentials are not removed properly in WebCore::DocumentThreadableLoader::loadRequest | - | 2016-10-02 |
| 356736 | minijail should signal failure when it cannot change user/group | - | 2016-10-02 |
| 356690 | Heap-use-after-free in WebCore::RenderObject::childAt | $1,000 | 2016-10-02 |
| 356653 | Security: Use after free in StyleEngine::createSheet | $3,000 | 2016-10-02 |
| 356652 | Extensions can modify the appearance of the Chrome Web Store | - | 2016-10-02 |
| 356540 | Heap-use-after-free in content::BufferedResourceLoader::Stop | - | 2016-10-02 |
| 356517 | Heap-use-after-free in WebCore::ReplaceSelectionCommand::removeRedundantStylesAndKeepStyleSpanInline | - | 2016-10-02 |
| 357173 | Use-after-free in WebCore::AsyncCallStackTracker::didRemoveEventListener | - | 2016-10-02 |
| 356235 | Untrusted synthetic gestures received in the browser are not verified | - | 2016-10-02 |
| 356220 | NO STACK | - | 2016-10-02 |
| 356211 | RETRY_AFTER_GC Failure Leak | - | 2016-10-02 |
| 356181 | Security: WebGL texImage2D can enable out-of-bounds memory access on Android | - | 2016-10-02 |
| 356095 | Heap-use-after-free in WebCore::HTMLBodyElement::insertedInto | $2,000 | 2016-10-02 |
| 356352 | ASSERTION FAILED: !webMediaPlayer(), Heap-use-after-free in blink::WebMediaPlayerClientImpl::load | $1,000 | 2016-10-02 |
| 355586 | UNKNOWN in int v8::internal::FlexibleBodyVisitor<v8::internal::NewSpaceScavenger, v8::internal::JSObject::BodyD | - | 2016-10-02 |
| 355438 | Use-after-free in WebCore::RenderBlockFlow::checkFloatsInCleanLine | - | 2016-10-02 |
| 355303 | UAF from RefCount Leak in Length::operator= | - | 2016-10-02 |
| 355036 | Security: integer overflow validating size in mojo::internal::FixedBuffer::Allocate | - | 2016-10-02 |
| 354931 | Security: UAF in NotifyAndDeleteIfDone/browser process crash related to WebSQL transactions in a Web Worker | - | 2016-10-02 |
| 354878 | Heap-use-after-free in WebCore::RenderText::firstAbstractInlineTextBox | - | 2016-10-02 |
| 355373 | ASSERTION FAILED: !widget || (widget->isPluginView()), UNKNOWN in WebCore::CompositedLayerMapping::updateGraphicsLayerConfiguration | - | 2016-10-02 |
| 354297 | use-of-uninitialized-memory in WebCore::RenderStyle::fontDescription, may cause use-after-free or some such | - | 2016-10-02 |
| 353895 | Heap-use-after-free in WebCore::StylePendingImage::cssValue | - | 2016-10-02 |
| 353894 | Heap-use-after-free in WebCore::StyleEngine::createSheet | - | 2016-10-02 |
| 354669 | Chrome_ChromeOS: Crash Report - net::QuicConnection::CanWrite | - | 2016-10-02 |
| 354058 | UNKNOWN in DecodeContextMap | - | 2016-10-02 |
| 353579 | Security: Android show full security for weak DH groups. | - | 2016-10-02 |
| 353577 | ASSERTION FAILED: cc < codePointsNumber, UNKNOWN in WebCore::MediaQueryTokenizer::nextToken | - | 2016-10-02 |
| 353224 | libwidevinecdm.so text section is writeable (rwx) | - | 2016-10-02 |
| 353058 | Heap-buffer-overflow in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
| 353035 | Heap-use-after-free in WebCore::MemoryCache::evict | - | 2016-10-02 |
| 353013 | Security: admin.google.com should have HSTS preloaded | - | 2016-10-02 |
| 352982 | CHECK failure in CHECK(object->map()->IsMap()) failed: ../src/heap-inl.h(818) | - | 2016-10-02 |
| 353621 | Use-after-free in WebCore::InspectorCSSAgent::collectAllDocumentStyleSheets | - | 2016-10-02 |
| 352941 | Use-after-free in WebCore::StyleSheetContents::startLoadingDynamicSheet | - | 2016-10-02 |
| 352929 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 352851 | Security: UaF in SpeechRecognitionBubbleImpl::~SpeechRecognitionBubbleImpl | $1,000 | 2016-10-02 |
| 352447 | Security: Use a narrowwhitelist for VFS names | - | 2016-10-02 |
| 352429 | Security: Junction Point directory traversal vulnerability - pwn2own 2014 | - | 2016-10-02 |
| 352395 | Pwn2Own (3/13/2014): Compromised renderers can set arbitrary clipboard formats | - | 2016-10-02 |
| 352380 | Geolocation permission is remembered on an HTTP site | - | 2016-10-02 |
| 352905 | Security: Incorrect origin shown on modal windows opened by sub-frames of chrome.google.com/webstore | - | 2016-10-02 |
| 352369 | Pwn2own (3/13/2014): VUPEN exploit. | - | 2016-10-02 |
| 352181 | ASSERTION FAILED: !CustomElementCallbackDispatcher::inCallbackDeliveryScope(), UNKNOWN in WebCore::CustomElementMicrotaskDispatcher::doDispatch | - | 2016-10-02 |
| 352178 | Heap-use-after-free in WebCore::SVGFontFaceElement::associatedFontElement | - | 2016-10-02 |
| 352083 | Security: Chrome for Android - URL bar spoof | $3,000 | 2016-10-02 |
| 352374 | Pwn2own (3/13/2014): Use-after-free in bindings | - | 2016-10-02 |
| 364511 | Buffer overflow vulnerability in glibc | - | 2016-10-02 |
| 364405 | Security: input events to plugins bypass regular user gesture tracking | - | 2016-10-02 |
| 364365 | Crash while creating a SPDY session | - | 2016-10-02 |
| 364066 | ASSERTION FAILED: !activeAnimations || !activeAnimations->isAnimationStyleChange(), Heap-use-after-free in WebCore::CSSAnimations::AnimationEventDelegate::maybeDispatch | - | 2016-10-02 |
| 364065 | SEGV in media::InMemoryUrlProtocol::Read | $1,000 | 2016-10-02 |
| 363873 | ASSERTION FAILED: !object || (object->isBox()), UNKNOWN in WebCore::CompositedLayerMapping::updateGraphicsLayerGeometry | $3,000 | 2016-10-02 |
| 363841 | Hosted app alerts from iframes show title of app, not domain of iframe | - | 2016-10-02 |
| 363631 | ASSERTION FAILED: !value || (value->isPrimitiveValue()), UNKNOWN in WebCore::StyleBuilderFunctions::applyValueCSSPropertyFontVariant | - | 2016-10-02 |
| 363390 | Security: 64-bit may leak kernel addresses via LDT | - | 2016-10-02 |
| 362887 | Security: SSL CRL Vulnerability in Android Chrome | - | 2016-10-02 |
| 362865 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
| 362898 | Heap-use-after-free in WebCore::Resource::checkNotify | - | 2016-10-02 |
| 362558 | Heap-use-after-free in content::VideoCaptureImpl::InitOnIOThread | - | 2016-10-02 |
| 362480 | Use-after-free in WebCore::Chrome::notifyPopupOpeningObservers | - | 2016-10-02 |
| 362110 | ASSERTION FAILED: positionOffset <= node->length(), UNKNOWN in WebCore::updatePositionAfterAdoptingTextReplacement | - | 2016-10-02 |
| 362109 | ASSERTION FAILED: i <= length, UNKNOWN in WebCore::WindowFeatures::WindowFeatures | - | 2016-10-02 |
| 361933 | Global-buffer-overflow in v8::internal::VisitorDispatchTable<void | - | 2016-10-02 |
| 362762 | Import qcms buffer overflow fix | - | 2016-10-02 |
| 362310 | Use-after-free in WebCore::MutableStylePropertySet::mergeAndOverrideOnConflict | - | 2016-10-02 |
| 360784 | Use-after-free in WebCore::RenderTextFragment::originalText | - | 2016-10-02 |
| 361608 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 360733 | Heap-buffer-overflow in v8::internal::Simulator::HandleRList | - | 2016-10-02 |
| 360798 | Security: openssl info leak | - | 2016-10-02 |
| 360595 | Heap-buffer-overflow in bits_to_runs | - | 2016-10-02 |
| 360448 | Eavesdrop on the user speech - abusing the old speech API | - | 2016-10-02 |
| 360431 | Heap-buffer-overflow in getNextNormalizedChar | - | 2016-10-02 |
| 360430 | ASSERTION FAILED: index < TypedArrayBase<T>::m_length, UNKNOWN in WebCore::FEDisplacementMap::applySoftware | - | 2016-10-02 |
| 360429 | ASSERTION FAILED: actualInfo->derefObjectFunction == wrapperTypeInfo.derefObjectFunction, UNKNOWN in WebCore::V8HTMLElement::createWrapper | - | 2016-10-02 |
| 360408 | Stack-buffer-overflow in opj_read_bytes_LE | - | 2016-10-02 |
| 360403 | Heap-buffer-overflow in bool WebCore::CSSTokenizer::parseURIInternal<unsigned char, unsigned short> | - | 2016-10-02 |
| 360478 | UNKNOWN in void v8::internal::String::Visit<v8::Utf8LengthHelper::Visitor, v8::internal::ConsStringCaptureOp> | - | 2016-10-02 |
| 360433 | Heap-use-after-free in uprv_strdup_46 | - | 2016-10-02 |
| 360504 | Security: I accidentially disabled relro on chromeos arm m35. | - | 2016-10-02 |
| 360481 | ASSERTION FAILED: !m_clusterStack.isEmpty(), UNKNOWN in WebCore::FastTextAutosizer::currentCluster | - | 2016-10-02 |
| 360205 | Heap-buffer-overflow in opj_mct_decode | - | 2016-10-02 |
| 360171 | ASSERTION FAILED: !m_clusterStack.isEmpty(), UNKNOWN in WebCore::FastTextAutosizer::currentCluster | - | 2016-10-02 |
| 360163 | Heap-use-after-free in WebCore::BreakingContext::commitAndUpdateLineBreakIfNeeded | - | 2016-10-02 |
| 360345 | Heap-use-after-free in media::DecryptingDemuxerStream::Stop | - | 2016-10-02 |
| 360344 | UNKNOWN in opj_j2k_read_SQcd_SQcc | - | 2016-10-02 |
| 360214 | Heap-use-after-free in WebCore::DocumentMarkerController::removeMarkersFromList | - | 2016-10-02 |
| 359525 | CHECK failure in CHECK(size_in_bytes <= kMaxBlockSize) failed: ../src/spaces.cc(2378) | - | 2016-10-02 |
| 360053 | Global-buffer-overflow in CFX_FaceCache::RenderGlyph | - | 2016-10-02 |
| 359134 | UNKNOWN in v8::internal::MemoryChunk::IsFlagSet | - | 2016-10-02 |
| 359130 | Heap-use-after-free in WebCore::SpeechSynthesisUtterance::startTime | - | 2016-10-02 |
| 359802 | ZDI-CAN-2245: Google Chrome ImageData Signedness Error Remote Code Execution VulnerabilityImageData Signedness Error Remote Code Execution Vulnerability | - | 2016-10-02 |
| 359454 | Security: Integer overflow allocating shared memory in AudioInputRendererHost::OnCreateStream | $3,000 | 2016-10-02 |
| 359602 | Heap-use-after-free in WebCore::InlineBox::root | - | 2016-10-02 |
| 358571 | Security: appengine.google.com has wildcard but not include_subdomains | - | 2016-10-02 |
| 358667 | Heap-buffer-overflow in void WebCore::CSSTokenizer::parseIdentifier<unsigned char> | - | 2016-10-02 |
| 358960 | Heap-use-after-free in content::MediaStreamAudioSinkOwner::OnReadyStateChanged | - | 2016-10-02 |
| 358813 | Heap-use-after-free in WebCore::Scrollbar::gestureEvent | - | 2016-10-02 |
| 369760 | UNKNOWN in content::WAVEDecoder::ReadChunkHeader | - | 2016-10-02 |
| 369759 | ASSERTION FAILED: positionOffset <= node->length(), UNKNOWN in WebCore::updatePositionAfterAdoptingTextReplacement | - | 2016-10-02 |
| 369621 | Crash in content::RendererClipboardWriteContext::WriteBitmapFromPixels | $500 | 2016-10-02 |
| 369615 | ASSERT !m_paintStateIndex failure in ~GraphicsContext, missing a restore(). | - | 2016-10-02 |
| 369848 | double-click allows to steal form history | - | 2016-10-02 |
| 369808 | Heap-use-after-free in void WebCore::ImageDecodingStore::insertCacheInternal<WebCore::ImageDecodingStore::ImageCacheEntry, | - | 2016-10-02 |
| 369517 | UNKNOWN in SkPath::isRectContour | - | 2016-10-02 |
| 369525 | ASSERTION FAILED: static_cast<FileError::ErrorCode>(code) != FileError::ABORT_ERR, Heap-use-after-free in v8::internal::GlobalHandles::Node::Release | $1,000 | 2016-10-02 |
| 368980 | Heap-buffer-overflow in ff_er_frame_end | - | 2016-10-02 |
| 369519 | ASSERTION FAILED: !tryCatch.HasCaught() || result.IsEmpty(), Heap-use-after-free in WebCore::InlineBox::dirtyLineBoxes | - | 2016-10-02 |
| 369127 | UNKNOWN in v8::internal::NoBarrier_Load | - | 2016-10-02 |
| 368551 | Use-after-free in WebCore::ResourcePtrBase::setResource | - | 2016-10-02 |
| 368978 | Bad-cast to WebCore::ShadowRoot from WebCore::Text;ShadowRoot.h:164:1 | - | 2016-10-02 |
| 368979 | UNKNOWN in v8::internal::NoBarrier_Load | - | 2016-10-02 |
| 367817 | Cross origin bypass with Object.observe(). | - | 2016-10-02 |
| 367812 | Security: AppCache allows MITM of same-origin shared hosting | - | 2016-10-02 |
| 367764 | UNKNOWN in SkValidatingReadBuffer::readString | - | 2016-10-02 |
| 367567 | Security: Any extension can debug any other extension (e.g. crosh) | $1,500 | 2016-10-02 |
| 367985 | UNKNOWN in android::MPEG4Source::stop | - | 2016-10-02 |
| 367544 | UNKNOWN in CJBig2_GSIDProc::decode_Arith | - | 2016-10-02 |
| 367508 | Use-after-free in WebCore::RenderObjectChildList::destroyLeftoverChildren | - | 2016-10-02 |
| 366781 | WebVector::initialize{From} should bounds check its size parameter | - | 2016-10-02 |
| 366694 | UNKNOWN in opj_read_bytes_LE | - | 2016-10-02 |
| 366693 | Global-buffer-overflow in CJS_PublicMethods::MakeFormatDate | - | 2016-10-02 |
| 366692 | Heap-use-after-free in Document::title | - | 2016-10-02 |
| 366690 | Heap-buffer-overflow in j2k_read_ppm_v3 | - | 2016-10-02 |
| 366947 | PSL matching should only apply to HTML forms | - | 2016-10-02 |
| 366797 | Security: UAF in mojo::internal::DecodePointerRaw | - | 2016-10-02 |
| 366510 | Heap-use-after-free in content::RenderFrameHostImpl::JavaScriptDialogClosed | - | 2016-10-02 |
| 366687 | Heap-buffer-overflow in load_truetype_glyph | - | 2016-10-02 |
| 366685 | Heap-buffer-overflow in CPDF_ColorSpace::TranslateImageLine | - | 2016-10-02 |
| 366683 | UNKNOWN in libc.so.6 | - | 2016-10-02 |
| 366682 | UNKNOWN in CFXMEM_FixedMgr::AllocLarge | - | 2016-10-02 |
| 366681 | UNKNOWN in CFXMEM_FixedMgr::Realloc | - | 2016-10-02 |
| 366686 | Heap-buffer-overflow in j2k_read_ppm_v3 | - | 2016-10-02 |
| 366496 | Mobile Chrome Sync tokens used by the mobile Chrome browser can be used to push extensions. | - | 2016-10-02 |
| 366688 | Heap-use-after-free in CPDFSDK_Document::GetInterForm | - | 2016-10-02 |
| 366689 | Heap-use-after-free in opj_stream_read_data | - | 2016-10-02 |
| 366182 | Use-after-free in std::_For_each<std::_Deque_unchecked_iterator<std::_Deque_val<std::_Deque_simple_types<appcache::App | - | 2016-10-02 |
| 365359 | Malicious page can escalate to content script privilege level when content script modifies page DOM | $1,000 | 2016-10-02 |
| 366251 | Security: CSP policy matching can be used as a timing oracle | - | 2016-10-02 |
| 365064 | Heap-use-after-free in WebCore::CompositedLayerMapping::~CompositedLayerMapping | $2,000 | 2016-10-02 |
| 365141 | Heap-use-after-free in media::Pipeline::StateTransitionTask | - | 2016-10-02 |
| 377416 | Heap-use-after-free in WebCore::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
| 377392 | Linux kernel futex() memory corruption vulnerability and exploit | $10,000 | 2016-10-02 |
| 377209 | UNKNOWN in v8::internal::MemoryChunk::heap | - | 2016-10-02 |
| 377193 | Heap-use-after-free in SkPathRef::resetToSize | - | 2016-10-02 |
| 377290 | UNKNOWN in v8::internal::Map::instance_type | - | 2016-10-02 |
| 376951 | Security: webgl draw buffers extension can expose unitialized video memory to webpage | $2,000 | 2016-10-02 |
| 376802 | Heap-buffer-overflow in decoder_decode | - | 2016-10-02 |
| 376748 | Heap-use-after-free in WebCore::ImageLoader::doUpdateFromElement | - | 2016-10-02 |
| 377118 | Security: Close manually opened tab via scripting | - | 2016-10-02 |
| 376800 | Heap-buffer-overflow in WebCore::TextResourceDecoder::checkForCSSCharset | - | 2016-10-02 |
| 375954 | Heap-use-after-free in WebCore::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
| 376438 | Heap-use-after-free in nextOnLine | - | 2016-10-02 |
| 375672 | ThreadSanitizer reports a use-after-free in DomSerializerTests.SerializeHTMLDOMWithEmptyHead | - | 2016-10-02 |
| 376433 | ASSERTION FAILED: obj->isRenderInline() || obj == this, UNKNOWN in WebCore::RenderBlockFlow::createLineBoxes | - | 2016-10-02 |
| 374904 | ASSERTION FAILED: !node || (node->isShadowRoot()), UNKNOWN in WebCore::TextIterator::advance | - | 2016-10-02 |
| 374443 | Heap-buffer-overflow in v8::internal::__RT_impl_Runtime_TypedArrayInitializeFromArrayLike | - | 2016-10-02 |
| 374452 | Network icon should be updated when a VPN disconnects | - | 2016-10-02 |
| 374052 | Heap-use-after-free in SkScaledImageCache::findAndLock | - | 2016-10-02 |
| 373312 | Heap-buffer-overflow in WebRtcIsacfix_Decode | - | 2016-10-02 |
| 374497 | Heap-use-after-free in WebCore::BaseMultipleFieldsDateAndTimeInputType::spinButtonElement | - | 2016-10-02 |
| 374665 | Heap-use-after-free in WebCore::SQLiteStatement::prepare | - | 2016-10-02 |
| 374176 | Security: no javascript: url pasting protection on android | - | 2016-10-02 |
| 372525 | Security: heap write access due to integer overflow on bspatch implementations | - | 2016-10-02 |
| 372413 | UNKNOWN in CFXMEM_Page::Free | - | 2016-10-02 |
| 373283 | UNKNOWN in v8::internal::NoBarrier_Load | - | 2016-10-02 |
| 372410 | Heap-buffer-overflow in CPDF_DIBSource::TranslateScanline24bpp | - | 2016-10-02 |
| 372820 | ASSERTION FAILED: !value || (value->isStepsTimingFunctionValue()), UNKNOWN in WebCore::CSSToStyleMap::mapAnimationTimingFunction | - | 2016-10-02 |
| 372411 | Global-buffer-overflow in CJS_PublicMethods::MakeFormatDate | - | 2016-10-02 |
| 372110 | Heap-use-after-free in SkImageFilter::filterImage | - | 2016-10-02 |
| 371380 | Heap-use-after-free in opj_read_from_memory | - | 2016-10-02 |
| 372206 | Crash on content::WebURLLoaderImpl::cancel | - | 2016-10-02 |
| 371813 | Heap-use-after-free in content::ResourceDispatcher::RemovePendingRequest | - | 2016-10-02 |
| 371237 | Heap-buffer-overflow in SkBitmapHeap::getBitmap | - | 2016-10-02 |
| 371240 | Global-buffer-overflow in SkBlitter::Choose | - | 2016-10-02 |
| 369860 | Security: ASAN heap-use-after-free in SVGElement::propertyFromAttribute | $2,000 | 2016-10-02 |
| 385268 | Heap-use-after-free in WebCore::RenderBlock::computeBlockPreferredLogicalWidths | - | 2016-10-02 |
| 385054 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 385002 | Heap-buffer-overflow in v8::internal::Simulator::HandleRList | - | 2016-10-02 |
| 384890 | Heap-use-after-free in WebCore::FrameLoaderStateMachine::advanceTo | - | 2016-10-02 |
| 384662 | Security: Possible integer overflow in CFX_BasicArray::Append | - | 2016-10-02 |
| 384365 | Heap-use-after-free in chrome_pdf::PDFiumPage::GetPage | - | 2016-10-02 |
| 384223 | Security: http basic authentication dialog from background tab is displayed over the active tab | - | 2016-10-02 |
| 383939 | Heap-use-after-free in JavaObjectWeakGlobalRef::get | - | 2016-10-02 |
| 384891 | Heap-buffer-overflow in chrome_pdf::AlphaBlend | - | 2016-10-02 |
| 383725 | [PowerProfiler] Browser crashes with active timeline recording for capturing power | - | 2016-10-02 |
| 383777 | ASSERTION FAILED: positionOffset <= node->length() | $1,000 | 2016-10-02 |
| 383703 | ASSERT_WITH_SECURITY_IMPLICATION(i <= length) in WebCore::Document::processArguments | - | 2016-10-02 |
| 382921 | Uninitialized members in OriginChipView | - | 2016-10-02 |
| 382820 | Heap-buffer-overflow in CPDF_DeviceCS::TranslateImageLine | - | 2016-10-02 |
| 382766 | Security: never build chrome-sandbox with ASAN coverage | - | 2016-10-02 |
| 382667 | Security: Integer overflow from "offset + size" everywhere | - | 2016-10-02 |
| 383704 | ASSERT_WITH_SECURITY_IMPLICATION(i <= length) in WebCore::WindowFeatures::WindowFeatures | - | 2016-10-02 |
| 382260 | Heap-use-after-free in content::ThreadedDataProvider::Stop | - | 2016-10-02 |
| 382639 | Security: Integer overflow in fpdfsdk/include/fsdk_mgr.h | - | 2016-10-02 |
| 382522 | Heap-use-after-free in media::MidiManager::CompleteInitializationInternal | - | 2016-10-02 |
| 382513 | UNKNOWN in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
| 382279 | Heap-use-after-free in WebCore::HTMLFrameElementBase::openURL | - | 2016-10-02 |
| 382601 | Integer overflow in FX_AllocStringW | - | 2016-10-02 |
| 382243 | UNKNOWN in CFXMEM_FixedMgr::AllocLarge | - | 2016-10-02 |
| 382242 | UNKNOWN in _CMapLookupCallback | - | 2016-10-02 |
| 382241 | Heap-buffer-overflow in CPDF_TrueTypeFont::LoadGlyphMap | - | 2016-10-02 |
| 382656 | Security: Integer overflow in ./core/include/fxcrt/fx_basic.h and ./core/include/fxcrt/fx_memory.h | - | 2016-10-02 |
| 382606 | Security: Integer overflow in javascript/Document.cpp | - | 2016-10-02 |
| 382239 | Heap-buffer-overflow in opj_j2k_update_image_data | - | 2016-10-02 |
| 382121 | Heap-use-after-free in content::RenderFrameImpl::didFinishLoad | - | 2016-10-02 |
| 381808 | Security: JavaScript can detect visited links via CSS nested <a><button> + getClientRects height (OSX) | $1,000 | 2016-10-02 |
| 381696 | Global-buffer-overflow in CFX_Font::LoadGlyphPath | - | 2016-10-02 |
| 382240 | Stack-buffer-overflow in IccLib_Translate | - | 2016-10-02 |
| 381521 | Heap-buffer-overflow in CFX_WideString::FromUTF16LE | - | 2016-10-02 |
| 381534 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 381465 | Crash when legacy EVP_PKEY outlives Java wrapper on Android 4.1.2. | - | 2016-10-02 |
| 381200 | Security: OpenSSL CCS Vulnerability | - | 2016-10-02 |
| 381031 | Attempting free in CJBig2_Context::~CJBig2_Context | - | 2016-10-02 |
| 380885 | Security: Cache-based SOP-Bypass for Images | $2,000 | 2016-10-02 |
| 380723 | Heap-buffer-overflow in SkValidatingReadBuffer::readRect | - | 2016-10-02 |
| 381244 | Heap-buffer-overflow in void SkMatrixConvolutionImageFilter::filterPixels<UncheckedPixelFetcher, true> | - | 2016-10-02 |
| 380512 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 379998 | Heap-use-after-free in WebCore::V8SVGTransformList::visitDOMWrapper | - | 2016-10-02 |
| 379856 | Heap-use-after-free in content::PeerConnectionAudioSinkOwner::OnData | - | 2016-10-02 |
| 379799 | UNKNOWN in unsafe_free | - | 2016-10-02 |
| 379656 | Security: Integer overflow leads to buffer overflow in PDF_EncodeText | - | 2016-10-02 |
| 380663 | Security: Safe Browsing for Executable Files can be bypassed by using the FileSystem API | $500 | 2016-10-02 |
| 379458 | Heap-buffer-overflow in WebRtcIsacfix_Decode | - | 2016-10-02 |
| 379271 | Security: New UserGestureIndicator created for every touch event. | - | 2016-10-02 |
| 378782 | Heap-buffer-overflow in matroska_read_seek | - | 2016-10-02 |
| 378512 | Security: Clicking "export" in Certificate Viewer can cause navigation to arbitrary filesystem paths | - | 2016-10-02 |
| 378469 | Heap-use-after-free in WebCore::GraphicsContext::drawImage | - | 2016-10-02 |
| 378179 | Heap-use-after-free in cricket::ChannelManager::StopVideoCapture | - | 2016-10-02 |
| 378175 | Heap-buffer-overflow in SkReadBuffer::readBitmap | - | 2016-10-02 |
| 378167 | ASSERTION FAILED: value.isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::backgroundRepeatPropertyValue | - | 2016-10-02 |
| 387844 | Use-of-uninitialized-value in CPDF_StreamParser::ParseNextElement | - | 2016-10-02 |
| 387843 | Use-of-uninitialized-value in EvalSegmentedFn | - | 2016-10-02 |
| 387841 | Use-of-uninitialized-value in CPDF_DIBSource::TranslateScanline24bpp | - | 2016-10-02 |
| 387840 | Use-of-uninitialized-value in T1_Load_Glyph | - | 2016-10-02 |
| 387845 | Use-of-uninitialized-value in FPDFAPI_inflate | - | 2016-10-02 |
| 387842 | Use-of-uninitialized-value in aes_decrypt_nb_4 | - | 2016-10-02 |
| 387837 | Use-of-uninitialized-value in opj_t2_read_packet_header | - | 2016-10-02 |
| 387826 | Use-of-uninitialized-value in cmsXYZ2Lab | - | 2016-10-02 |
| 387835 | Use-of-uninitialized-value in _DrawGouraud | - | 2016-10-02 |
| 387834 | Use-of-uninitialized-value in CRYPT_ArcFourCryptBlock | - | 2016-10-02 |
| 387833 | Use-of-uninitialized-value in CPDF_Parser::LoadCrossRefV4 | - | 2016-10-02 |
| 387832 | Use-of-uninitialized-value in CXML_Parser::SkipLiterals | - | 2016-10-02 |
| 387831 | Use-of-uninitialized-value in CPDF_DeviceCS::GetRGB | - | 2016-10-02 |
| 387827 | Use-of-uninitialized-value in CXML_Parser::SkipLiterals | - | 2016-10-02 |
| 387838 | Use-of-uninitialized-value in CCodec_RLScanlineDecoder::Create | - | 2016-10-02 |
| 387839 | Use-of-uninitialized-value in _CompositeRow_Argb2Rgb_NoBlend | - | 2016-10-02 |
| 387836 | Use-of-uninitialized-value in CFX_Matrix::TransformRect | - | 2016-10-02 |
| 387816 | Use-of-uninitialized-value in CXML_Parser::ParseElement | - | 2016-10-02 |
| 387824 | Use-of-uninitialized-value in _A85Decode | - | 2016-10-02 |
| 387820 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
| 387819 | Use-of-uninitialized-value in CPDF_SimpleParser::GetWord | - | 2016-10-02 |
| 387818 | Use-of-uninitialized-value in CPDF_StreamParser::GetNextWord | - | 2016-10-02 |
| 387817 | Use-of-uninitialized-value in _FaxG4GetRow | - | 2016-10-02 |
| 387821 | Use-of-uninitialized-value in FXSYS_round | - | 2016-10-02 |
| 387815 | Use-of-uninitialized-value in CPDF_RenderStatus::GetFillArgb | - | 2016-10-02 |
| 387814 | Use-of-uninitialized-value in CXML_Parser::GetTagName | - | 2016-10-02 |
| 387813 | Use-of-uninitialized-value in CXML_Parser::SkipLiterals | - | 2016-10-02 |
| 387825 | Use-of-uninitialized-value in CLZWDecoder::Decode | - | 2016-10-02 |
| 387822 | Use-of-uninitialized-value in CXML_Parser::GetCharRef | - | 2016-10-02 |
| 387811 | Use-of-uninitialized-value in CStretchEngine::ContinueStretchHorz | - | 2016-10-02 |
| 387809 | Use-of-uninitialized-value in CPDF_SeparationCS::GetRGB | - | 2016-10-02 |
| 387808 | Use-of-uninitialized-value in _RGB_Blend | - | 2016-10-02 |
| 387807 | Use-of-uninitialized-value in FXSYS_StrToInt<int, | - | 2016-10-02 |
| 387806 | Use-of-uninitialized-value in CJBig2_Context::parseSegmentHeader | - | 2016-10-02 |
| 387805 | Use-of-uninitialized-value in CJBig2_Context::parseSegmentHeader | - | 2016-10-02 |
| 387803 | Use-of-uninitialized-value in CPDF_SimpleParser::ParseWord | - | 2016-10-02 |
| 387812 | Use-of-uninitialized-value in IccLib_Translate | - | 2016-10-02 |
| 387801 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
| 387800 | Use-of-uninitialized-value in _cmsReadHeader | - | 2016-10-02 |
| 387802 | Use-of-uninitialized-value in CXML_Parser::ParseElement | - | 2016-10-02 |
| 387798 | Use-of-uninitialized-value in CJBig2_Context::parseSymbolDict | - | 2016-10-02 |
| 387796 | Use-of-uninitialized-value in CFX_MapByteStringToPtr::operator | - | 2016-10-02 |
| 387793 | Use-of-uninitialized-value in CPDF_TrueTypeFont::LoadGlyphMap | - | 2016-10-02 |
| 387792 | Use-of-uninitialized-value in compareCID | - | 2016-10-02 |
| 387791 | Use-of-uninitialized-value in CPDF_Parser::LoadCrossRefV5 | - | 2016-10-02 |
| 387790 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
| 387789 | Use-of-uninitialized-value in CPDF_StreamParser::ReadString | - | 2016-10-02 |
| 387788 | Use-of-uninitialized-value in CXML_Parser::ParseElement | - | 2016-10-02 |
| 387786 | Use-of-uninitialized-value in CPDF_StreamParser::ReadHexString | - | 2016-10-02 |
| 387785 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
| 387797 | Use-of-uninitialized-value in tt_glyph_load | - | 2016-10-02 |
| 387783 | Use-of-uninitialized-value in CPDF_DataAvail::GetObject | - | 2016-10-02 |
| 387778 | Use-of-uninitialized-value in CXML_Parser::GetCharRef | - | 2016-10-02 |
| 387781 | Use-of-uninitialized-value in T1_Load_Glyph | - | 2016-10-02 |
| 387780 | Use-of-uninitialized-value in _FaxGetRun | - | 2016-10-02 |
| 387779 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
| 387784 | Use-of-uninitialized-value in PDF_DecodeText | - | 2016-10-02 |
| 387777 | Use-of-uninitialized-value in MatShaperEval16 | - | 2016-10-02 |
| 387776 | Use-of-uninitialized-value in CPDF_Parser::LoadCrossRefV4 | - | 2016-10-02 |
| 387775 | Use-of-uninitialized-value in CPDF_RenderStatus::LoadSMask | - | 2016-10-02 |
| 387774 | Use-of-uninitialized-value in CPDF_DataAvail::GetObject | - | 2016-10-02 |
| 387506 | Use-of-uninitialized-value in FXSYS_round | - | 2016-10-02 |
| 387782 | Use-of-uninitialized-value in CPDF_DIBSource::DownSampleScanline | - | 2016-10-02 |
| 387389 | Heap-use-after-free in WebCore::DocumentV8Internal::getElementByIdMethodCallbackForMainWorld | $2,000 | 2016-10-02 |
| 387371 | Bad-cast to gfx::MultiAnimation from gfx::ThrobAnimation;tab.cc:1096:11 | - | 2016-10-02 |
| 387315 | Bad-cast to WebCore::HTMLLabelElement from WebCore::SVGUnknownElement;WebNode.h:164:16 | - | 2016-10-02 |
| 387313 | Use-of-uninitialized-value in t1_parse_font_matrix | - | 2016-10-02 |
| 387211 | Bad-cast to WebCore::RenderInline from WebCore::RenderBlockFlow;RenderInline.h:195:1 | - | 2016-10-02 |
| 387037 | DownloadPathIsDangerous should verify that the path is a directory | - | 2016-10-02 |
| 387033 | Navigation bypass for web -> file | - | 2016-10-02 |
| 387031 | Security: V8 Array length getter override | - | 2016-10-02 |
| 387016 | Bad-cast to WebCore::SpeechSynthesisUtterance from WebCore::SpeechSynthesis; V8EventTargetCustom.cpp:52:5 | - | 2016-10-02 |
| 387470 | Heap-use-after-free in WebCore::DocumentThreadableLoader::notifyFinished | - | 2016-10-02 |
| 387014 | Use-of-uninitialized-value in CPDF_RenderStatus::GetStrokeArgb | - | 2016-10-02 |
| 387013 | Use-of-uninitialized-value in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
| 387011 | Use-of-uninitialized-value in CPDF_StandardSecurityHandler::GetUserPassword | - | 2016-10-02 |
| 387010 | Use-of-uninitialized-value in sfnt_open_font | - | 2016-10-02 |
| 386730 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
| 386729 | Use-of-uninitialized-value in CPDF_RenderStatus::GetFillArgb | - | 2016-10-02 |
| 386728 | Use-of-uninitialized-value in CPDF_DeviceCS::GetRGB | - | 2016-10-02 |
| 386034 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 386988 | Full chain exploit + sandbox escape: Array.concat -> extension install -> download exec | $30,000 | 2016-10-02 |
| 385691 | Bad cast from DevToolsNetworkTransactionFactory to HttpNetworkLayer | - | 2016-10-02 |
| 385646 | Heap-buffer-overflow in vp9_resize_frame_buffers | - | 2016-10-02 |
| 391570 | Stack-buffer-overflow in content::webcrypto::platform::CreatePublicKeyAlgorithm | $1,000 | 2016-10-02 |
| 391472 | Use-of-uninitialized-value in CPDF_DeviceNCS::GetRGB | - | 2016-10-02 |
| 391470 | Use-of-uninitialized-value in CPDF_RenderStatus::DrawShading | - | 2016-10-02 |
| 391301 | Use-of-uninitialized-value in cc::SolidColorDrawQuad::SetNew | - | 2016-10-02 |
| 391023 | Uninitialized IPC message in OutOfProcessPPAPITest.ImageData | - | 2016-10-02 |
| 391004 | Use-of-uninitialized-value in SkUnPreMultiply::UnPreMultiplyPreservingByteOrder | - | 2016-10-02 |
| 391001 | Use-of-uninitialized-value in SkFlatDictionary<SkPaint, SkPaint::FlatteningTraits>::findAndReturnMutableF | $500 | 2016-10-02 |
| 391000 | Use-of-uninitialized-value in SkBitmap::setAlphaType | - | 2016-10-02 |
| 390999 | Use-of-uninitialized-value in WebCore::OpaqueRegionSkia::markRectAsNonOpaque | - | 2016-10-02 |
| 390997 | Use-of-uninitialized-value in FT_Outline_Get_Orientation | - | 2016-10-02 |
| 390973 | Use-of-uninitialized-value in IPC::ChannelPosix::ProcessOutgoingMessages | - | 2016-10-02 |
| 390970 | Use-of-uninitialized-value in IPC::ChannelPosix::ProcessOutgoingMessages | - | 2016-10-02 |
| 390945 | Use-of-uninitialized-value in put_vp8_epel16_h6v6_c | - | 2016-10-02 |
| 390944 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
| 390941 | Use-of-uninitialized-value in vp8_h_loop_filter16_c | - | 2016-10-02 |
| 390936 | Use-after-poison in WebCore::ThreadHeap<WebCore::FinalizedHeapObjectHeader>::addToFreeList | - | 2016-10-02 |
| 390928 | Heap-use-after-free in v8::internal::GlobalHandles::Create | $4,000 | 2016-10-02 |
| 390711 | Security: umount can be called from non-root user via fusermount | - | 2016-10-02 |
| 390567 | UNKNOWN in base::Time::LocalMidnight | - | 2016-10-02 |
| 390709 | Security: Local Priv Esc - pppd malformed config file could lead to code execution in suid binary | - | 2016-10-02 |
| 390601 | Use-of-uninitialized-value in CFX_WideString::InitStr | - | 2016-10-02 |
| 390570 | Heap-use-after-free in WebCore::MediaValues::calculateMediaType | - | 2016-10-02 |
| 390569 | Heap-use-after-free in WebCore::RenderBlockFlow::computeInlinePreferredLogicalWidths | - | 2016-10-02 |
| 390624 | Security: Extensions can spoof the list of host permissions in the permission dialog | $1,000 | 2016-10-02 |
| 390563 | Heap-use-after-free in content::ChildSharedBitmapManager::FreeSharedMemory | - | 2016-10-02 |
| 390314 | Use-of-uninitialized-value in WebCore::PositionOptions::PositionOptions | - | 2016-10-02 |
| 390308 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-02 |
| 390304 | Use-of-uninitialized-value in webrtc::BuildMediaDescription | - | 2016-10-02 |
| 390176 | Heap-use-after-free in WebCore::HTMLImportLoader::removeImport | - | 2016-10-02 |
| 389285 | Heap-use-after-free in WebCore::RenderInline::inlineElementContinuation | - | 2016-10-02 |
| 389316 | Use-of-uninitialized-value in WebCore::TransformationMatrix::blend | - | 2016-10-02 |
| 389451 | Security: SDCH dictionary URL check can be bypassed | - | 2016-10-02 |
| 389570 | Heap-buffer-overflow in convolveVertically_SSE2 | - | 2016-10-02 |
| 389573 | Use-of-uninitialized-value in v8::internal::Decoder<v8::internal::Simulator>::DecodeBranchSystemException | - | 2016-10-02 |
| 389595 | Use-of-uninitialized-value in void v8::internal::Simulator::AddSubHelper<long> | - | 2016-10-02 |
| 389734 | Security: You can spoof any domain in the URL bar | $500 | 2016-10-02 |
| 390069 | Use-of-uninitialized-value in read_tag_lutmABType | - | 2016-10-02 |
| 390174 | Heap-use-after-free in WebCore::KURL::~KURL | $2,000 | 2016-10-02 |
| 389574 | Global-buffer-overflow in SkBitmap::ReadRawPixels | - | 2016-10-02 |
| 389223 | Chromoting host ignores NAT traversal policy | - | 2016-10-02 |
| 389219 | Use-of-uninitialized-value in WebCore::BiquadDSPKernel::updateCoefficientsIfNecessary | $500 | 2016-10-02 |
| 389216 | Use-of-uninitialized-value in WebCore::AudioContext::scheduleNodeDeletion | - | 2016-10-02 |
| 389204 | CRASH: media::AudioRendererMixer::OnRenderError() | - | 2016-10-02 |
| 388771 | Heap-use-after-free in extensions::V8SchemaRegistry::GetSchema | - | 2016-10-02 |
| 388762 | Use-after-free in content::LegacyRenderWidgetHostHWND::UpdateParent | - | 2016-10-02 |
| 388759 | NO STACK | - | 2016-10-02 |
| 389280 | Use-of-uninitialized-value in validate_layout | - | 2016-10-02 |
| 388757 | Use-after-free in WebCore::RenderBlockFlow::addOverhangingFloats | - | 2016-10-02 |
| 388665 | Penguins Puzzle WebGL game frequent Aw Snap | $3,000 | 2016-10-02 |
| 388294 | Heap-use-after-free in v8::HandleScope::Initialize | $1,000 | 2016-10-02 |
| 388267 | Use-after-poison in WebCore::IDBDatabase::trace | - | 2016-10-02 |
| 388135 | Use-of-uninitialized-value in CPDF_CMap::GetNextChar | - | 2016-10-02 |
| 388134 | Use-of-uninitialized-value in _SetLum | - | 2016-10-02 |
| 388133 | Use-of-uninitialized-value in CFX_BidiChar::AppendChar | - | 2016-10-02 |
| 388070 | Heap-buffer-overflow in media::FFmpegDemuxer::Seek | - | 2016-10-02 |
| 388058 | Heap-use-after-free in cc::PictureLayerTiling::TilingEvictionTileIterator::Initialize | - | 2016-10-02 |
| 387861 | Use-of-uninitialized-value in FPDFAPI_FT_DivFix | - | 2016-10-02 |
| 387852 | Use-of-uninitialized-value in aes_decrypt_nb_4 | - | 2016-10-02 |
| 387860 | Use-of-uninitialized-value in FXSYS_atoi | - | 2016-10-02 |
| 387856 | Use-of-uninitialized-value in _JpegScanSOI | - | 2016-10-02 |
| 387855 | Use-of-uninitialized-value in _FaxSkipEOL | - | 2016-10-02 |
| 387854 | Use-of-uninitialized-value in CPDF_RenderStatus::DrawShading | - | 2016-10-02 |
| 387853 | Use-of-uninitialized-value in FPDFAPI_inflate | - | 2016-10-02 |
| 387857 | Use-of-uninitialized-value in CPDF_SimpleParser::ParseWord | - | 2016-10-02 |
| 387850 | Use-of-uninitialized-value in FXSYS_atoi64 | - | 2016-10-02 |
| 387848 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
| 387847 | Use-of-uninitialized-value in opj_j2k_read_header_procedure | - | 2016-10-02 |
| 387846 | Use-of-uninitialized-value in _FaxGetRun | - | 2016-10-02 |
| 398235 | Security: possible another uninit memory with jpeg parsing | - | 2016-10-02 |
| 397834 | Use-of-uninitialized-value in CFX_WideString::InitStr | - | 2016-10-02 |
| 397835 | Use-of-uninitialized-value in chrome_pdf::PDFiumEngine::Paint | - | 2016-10-02 |
| 398109 | Security: Potential kernel privilege escalation when CONFIG_PPPOL2TP is enabled | - | 2016-10-02 |
| 397396 | Investigate lifetime of the NativeWindow parent in ExtensionUninstallDialog | - | 2016-10-02 |
| 398198 | Use-after-free in blink::WebSharedWorkerImpl::stopWorkerThread | $1,500 | 2016-10-02 |
| 397258 | Integer overflow from "offset + size" in extension.h and fpdfview.cpp | - | 2016-10-02 |
| 397549 | All of cc_unittests failing on yakju-clang-clankium | - | 2016-10-02 |
| 397656 | Heap-use-after-free in media::Pipeline::ErrorChangedTask | - | 2016-10-02 |
| 396961 | HTTP authentication dialog doesn't replace web contents when you type in to URL bar | - | 2016-10-02 |
| 396447 | Hooking up a remote audio track to local media stream would crash | - | 2016-10-02 |
| 396255 | Security: Uninitialized value possible in CJS_PublicMethods::MakeFormatDate | - | 2016-10-02 |
| 396054 | Security: Microphone access not blocked if you lock your phone. | $500 | 2016-10-02 |
| 397130 | HandleCloserAgent skips every other handle | - | 2016-10-02 |
| 395441 | Google Chrome not clearing the account data properly | - | 2016-10-02 |
| 395411 | ASSERTION FAILED: actualInfo->derefObjectFunction == wrapperTypeInfo.derefObjectFunction, UNKNOWN in blink::V8Event::createWrapper | $500 | 2016-10-02 |
| 395410 | Heap-use-after-free in syncer::SyncBackupManager::Init | $1,000 | 2016-10-02 |
| 395409 | Use-after-free in blink::MediaQueryList::stop | - | 2016-10-02 |
| 395679 | V8 executable page caps are dangerously high | - | 2016-10-02 |
| 395641 | UNKNOWN in SkImageFilter::Common::unflatten | - | 2016-10-02 |
| 395972 | Improper handling of calc parsing results in read access to pointer addresses | - | 2016-10-02 |
| 395461 | Use-after-free in CPDFSDK_PageView::LoadFXAnnots | - | 2016-10-02 |
| 395650 | SEGV in LocalWriteClosure::writeBlobToFileOnIOThread | - | 2016-10-02 |
| 395351 | Security: Chrome XSS Filter Bypassing | - | 2016-10-02 |
| 394902 | Use-after-free in several skia routines of memory freed by skia.dll!DWriteFontTypeface::`scalar deleting destructor' | - | 2016-10-02 |
| 395266 | Security: CJS_PublicMethods::StrRTrim() looks suspicious, may under/overflow | - | 2016-10-02 |
| 394026 | Heap-use-after-free in WebCore::Element::attrIfExists | - | 2016-10-02 |
| 393981 | Uninitialized IPC message in PopupBlockerTabHelper::ShowBlockedPopup | - | 2016-10-02 |
| 393833 | Use-of-uninitialized-value in content::webcrypto::platform::CreatePublicKeyAlgorithm | - | 2016-10-02 |
| 393831 | Use-of-uninitialized-value in CJS_PublicMethods::MakeRegularDate | - | 2016-10-02 |
| 393829 | Heap-use-after-free in blink::AXNodeObject::textUnderElement | - | 2016-10-02 |
| 394222 | Use-of-uninitialized-value in final_reordering_syllable | - | 2016-10-02 |
| 393938 | Uninitialized IPC message in PPB_Instance_Proxy::DeliverFrame | - | 2016-10-02 |
| 393605 | Heap-use-after-free in CPDF_Color::~CPDF_Color | - | 2016-10-02 |
| 393765 | Tracking bug for internal security fixes for Chrome 36, Release 0 | - | 2016-10-02 |
| 393595 | Use-after-free in WebCore::CustomElementMicrotaskRunQueue::dispatch | - | 2016-10-02 |
| 393572 | Padlock is shown after refresh despite displaying mixed content | - | 2016-10-02 |
| 393452 | UNKNOWN in memset | - | 2016-10-02 |
| 393603 | Use-of-uninitialized-value in CPDF_RenderStatus::GetStrokeArgb | - | 2016-10-02 |
| 393744 | Use-after-poison in WebCore::HeapPage<WebCore::FinalizedHeapObjectHeader>::markOrphaned | - | 2016-10-02 |
| 393602 | Heap-buffer-overflow in CCodec_FlateModule::FlateOrLZWDecode | - | 2016-10-02 |
| 393312 | Heap-use-after-free in WebCore::EventHandlerRegistry::documentDetached | - | 2016-10-02 |
| 393425 | Use-after-free in WebCore::FileReader::doAbort | - | 2016-10-02 |
| 393448 | Use-after-free in WebCore::CompositeEditCommand::replaceTextInNodePreservingMarkers | - | 2016-10-02 |
| 393221 | Heap-use-after-free in net::IOBuffer::data | - | 2016-10-02 |
| 393401 | Popups opened from a sandboxed iframe are not themselves sandboxed | $500 | 2016-10-02 |
| 392723 | Use-of-uninitialized-value in SkRect::setBoundsCheck | - | 2016-10-02 |
| 392598 | Use-after-free crash [@BrowserWindowCocoa::UpdateDevTools] | - | 2016-10-02 |
| 392719 | heap-use-after-free in CPDF_Color::~CPDF_Color | - | 2016-10-02 |
| 392510 | login_ChromeProfileSanitary indicates that Chrome is writing cookies to the Login profile | - | 2016-10-02 |
| 392720 | Use-of-uninitialized-value in CPDF_DocPageData::ReleaseColorSpace | - | 2016-10-02 |
| 392721 | Use-of-uninitialized-value in CXML_Parser::GetTagName | - | 2016-10-02 |
| 391929 | Potential integer overflow in fpdf_render_loadimage.cpp | - | 2016-10-02 |
| 392718 | Use-of-uninitialized-value in extensions::FrameNavigationState::SetNavigationCommitted | - | 2016-10-02 |
| 391905 | Use-of-uninitialized-value in icu_46::RegexMatcher::findUsingChunk | - | 2016-10-02 |
| 391910 | Use-of-uninitialized-value in WebCore::ErrorEventV8Internal::linenoAttributeGetterCallback | - | 2016-10-02 |
| 406562 | Vulnerability reported in net-misc/strongswan | - | 2016-10-02 |
| 406557 | Vulnerability reported in x11-libs/pixman | - | 2016-10-02 |
| 406142 | Heap-buffer-overflow in CFX_WideString::FromUTF16LE | - | 2016-10-02 |
| 405588 | Heap-buffer-overflow in CPDF_DeviceCS::GetRGB | - | 2016-10-02 |
| 406549 | Vulnerability reported in net-firewall/iptables | - | 2016-10-02 |
| 406548 | Vulnerability reported in dev-libs/libxml2 | - | 2016-10-02 |
| 406546 | Vulnerability reported in dev-libs/expat | - | 2016-10-02 |
| 406144 | Global-buffer-overflow in CFX_Font::LoadGlyphPath | - | 2016-10-02 |
| 404529 | Heap-use-after-free in blink::ImageQualityController::highQualityRepaintTimerFired | - | 2016-10-02 |
| 405416 | Stack-buffer-overflow in avpriv_aac_parse_header | - | 2016-10-02 |
| 404511 | Bad-cast to blink::IDBRequest from invalid vptrblink::GarbageCollectedFinalized<blink::IDBRequest>::finalizeGarbageCollectedObject;blink::HeapPage<blink::FinalizedHeapObjectHeader>::sweep;blink::ThreadHeap<blink::FinalizedHeapObjectHeader>::sweep | $3,500 | 2016-10-02 |
| 405421 | Heap-use-after-free in CPDF_IndexedCS::~CPDF_IndexedCS | - | 2016-10-02 |
| 405417 | Heap-use-after-free in SkOpSegment::addT | $1,000 | 2016-10-02 |
| 405335 | Heap-use-after-free in RemoteMediaPlayerManager::DidDownloadPoster | - | 2016-10-02 |
| 404513 | Heap-use-after-free in blink::FileReader::doAbort | - | 2016-10-02 |
| 403596 | Security: __lookupGetter__ and __lookupSetter__ can be used to leak all cross-origin data | - | 2016-10-02 |
| 403276 | Heap-use-after-free in blink::Document::didRemoveAllPendingStylesheet | $2,000 | 2016-10-02 |
| 403013 | use-after-free in mojo::internal::WeakServiceProvider::Clear | - | 2016-10-02 |
| 403665 | Heap-use-after-free in blink::TreeScopeAdopter::moveTreeToNewScope | - | 2016-10-02 |
| 404300 | Security: Blink inadequately whitelists child frames by name in access checks | - | 2016-10-02 |
| 404462 | Heap-use-after-free in blink::RenderBlockFlow::determineStartPosition | - | 2016-10-02 |
| 403409 | V8 Runtime_ArrayConcat uninitialized memory leak | $4,500 | 2016-10-02 |
| 402479 | Use-after-free in IDMap<blink::WebIDBCallbacks,1>::Releaser<1,0>::release_all | - | 2016-10-02 |
| 402407 | Heap-use-after-free in blink::RenderLayerScrollableArea::updateCompositingLayersAfterScroll | $3,000 | 2016-10-02 |
| 402297 | Heap-buffer-overflow in bracketAddOpening | - | 2016-10-02 |
| 402263 | Heap-use-after-free in blink::MediaQueryMatcher::viewportChanged | - | 2016-10-02 |
| 402260 | Heap-use-after-free in CPDF_Color::SetValue | $3,000 | 2016-10-02 |
| 402255 | Heap-use-after-free in blink::DocumentOrderedMap::add | - | 2016-10-02 |
| 402957 | Use-after-free in speech - saying "Hello" during the incognito window has closed | $2,000 | 2016-10-02 |
| 402702 | Security: Potential unsafe random number generation | - | 2016-10-02 |
| 402653 | Use-after-free from ASAN base::PlatformThreadRef::is_null() | - | 2016-10-02 |
| 401993 | Heap-use-after-free in unsigned long std::__1::__tree<std::__1::__value_type<unsigned int, std::__ | - | 2016-10-02 |
| 402240 | Heap-buffer-overflow in vp9_decode_frame | - | 2016-10-02 |
| 401463 | Bad-cast to blink::RenderBox from blink::RenderText;RenderBox.h:769:1 | $3,000 | 2016-10-02 |
| 401372 | Heap-use-after-free in CPDF_IndexedCS::~CPDF_IndexedCS | $3,000 | 2016-10-02 |
| 401364 | Heap-use-after-free in base::subtle::RefCountedThreadSafeBase::Release | - | 2016-10-02 |
| 401363 | Heap-use-after-free in blink::WebPagePopupImpl::closePopup | - | 2016-10-02 |
| 401362 | Heap-use-after-free in blink::RenderBox::pixelSnappedClientHeight | $2,000 | 2016-10-02 |
| 402218 | Bad-cast to blink::MediaQueryListListener from invalid vptr;ScriptedAnimationController.cpp:181:9 | - | 2016-10-02 |
| 401995 | Heap-buffer-overflow in CFX_ByteTextBuf::AppendChar | - | 2016-10-02 |
| 401580 | Heap-double-free in CFX_PathData::~CFX_PathData | - | 2016-10-02 |
| 400511 | Use-after-free in content::WebThreadBase::TaskObserverAdapter::WillProcessTask | - | 2016-10-02 |
| 400339 | Bad-cast to blink::ShadowRoot from blink::HTMLDocument;ShadowRoot.h:165:1 | - | 2016-10-02 |
| 400950 | Tracking bug for internal security fixes for Chrome 36, Release 1 | - | 2016-10-02 |
| 401115 | Security: UAF with Blob creation and Shared Workers | $1,500 | 2016-10-02 |
| 400996 | Heap-use-after-free in CPDF_TextStateData::~CPDF_TextStateData | $2,000 | 2016-10-02 |
| 400476 | Heap-use-after-free in blink::Event::path | $3,000 | 2016-10-02 |
| 399654 | UNKNOWN in v8::base::NoBarrier_Load | - | 2016-10-02 |
| 399495 | Heap-use-after-free in blink::WorkerSharedTimer::OnTimeout | $3,000 | 2016-10-02 |
| 399473 | Security: setpriority() is broadly allowed and allows to interact with other processes | - | 2016-10-02 |
| 399321 | Heap-use-after-free in blink::constructBidiRunsForLine | - | 2016-10-02 |
| 398925 | Security: SPDY connection sharing logic errors allows for MITM | $1,000 | 2016-10-02 |
| 399783 | Chrome_ChromeOS: Crash Report - blink::GraphicsLayer::setContentsOpaque | - | 2016-10-02 |
| 399768 | Security: NaCl inner sandbox escape on Windows due to mmap hole bug | - | 2016-10-02 |
| 399655 | Bad-cast to SessionService from invalid vptr;bind_internal.h:248:12 | $1,500 | 2016-10-02 |
| 398818 | Heap-use-after-free in blink::TreeScope::clearScopedStyleResolver | - | 2016-10-02 |
| 398438 | Heap-use-after-free in blink::Document::didRemoveAllPendingStylesheet | $2,000 | 2016-10-02 |
| 398384 | Security: Crash in memcpy in chrome_pdf::CopyImage | $3,000 | 2016-10-02 |
| 411165 | Use-of-uninitialized-value in std::__1::pair<std::__1::pair<WTF::StringImpl**, bool>, unsigned int> WTF:: | - | 2016-10-02 |
| 411160 | Use-of-uninitialized-value in cc::GLRenderer::EnqueueTextureQuad | - | 2016-10-02 |
| 411163 | Use-of-uninitialized-value in FXSYS_round | - | 2016-10-02 |
| 411162 | Use-of-uninitialized-value in webrtc::AudioDecoder::ConvertSpeechType | - | 2016-10-02 |
| 411161 | Use-of-uninitialized-value in CPDF_RenderStatus::GetFillArgb | - | 2016-10-02 |
| 411154 | Use-of-uninitialized-value in CPDF_DocPageData::ReleasePattern | - | 2016-10-02 |
| 411026 | Heap-use-after-free in blink::PersistentBase<blink::ThreadLocalPersistents< | - | 2016-10-02 |
| 410912 | UNKNOWN in v8::internal::MemoryChunk::IsFlagSet | - | 2016-10-02 |
| 410556 | UNKNOWN in v8::internal::JSFunction::context | $3,000 | 2016-10-02 |
| 410552 | Heap-buffer-overflow in SkOpSegment::findNextOp | $1,500 | 2016-10-02 |
| 410326 | Heap-use-after-free in CPDFSDK_PageView::LoadFXAnnots | - | 2016-10-02 |
| 411156 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
| 411159 | Use-of-uninitialized-value in content::MessageChannel::DrainEarlyMessageQueue | - | 2016-10-02 |
| 411133 | Bad-cast to cricket::WebRtcVoiceMediaChannel from webrtc::NetEqImpl;webrtcvideoengine.cc:1599:9 | - | 2016-10-02 |
| 409695 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
| 409692 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
| 409508 | Heap-use-after-free in blink::PODIntervalTree<int,blink::FloatingObject | - | 2016-10-02 |
| 409507 | Use-of-uninitialized-value in CFX_ByteString::~CFX_ByteString | - | 2016-10-02 |
| 410030 | CHECK failure in CHECK(!v8::internal::FLAG_enable_slow_asserts || (object->IsJSObject())) fa | - | 2016-10-02 |
| 409880 | Heap-use-after-free in cricket::WebRtcVoiceMediaChannel::SetupSharedBandwidthEstimation | - | 2016-10-02 |
| 409454 | Fetch event shouldn't fire for preflight requests | - | 2016-10-02 |
| 409506 | Heap-use-after-free in blink::AXNodeObject::document | - | 2016-10-02 |
| 409030 | After lock my Account login directly after clicking on google task manager | - | 2016-10-02 |
| 409023 | Heap-buffer-overflow in SkScalerContext_DW::generateImage | - | 2016-10-02 |
| 408739 | Heap-use-after-free in content::MessageChannel::DrainEarlyMessageQueue | - | 2016-10-02 |
| 409475 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | $3,000 | 2016-10-02 |
| 409373 | Heap-use-after-free in CPDF_Color::~CPDF_Color | $1,000 | 2016-10-02 |
| 408426 | Security: Page can run arbitrary code in the context of a UserGestureIndicator | - | 2016-10-02 |
| 408541 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | $3,000 | 2016-10-02 |
| 408154 | Heap-buffer-overflow in CPDF_DIBSource::DownSampleScanline | - | 2016-10-02 |
| 408164 | Heap-use-after-free in CPDF_ShadingObject::~CPDF_ShadingObject | $1,000 | 2016-10-02 |
| 408532 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | $1,000 | 2016-10-02 |
| 408160 | Bad-cast to blink::HTMLUnknownElement from blink::HTMLElement;ScriptWrappable.h:90:16 | - | 2016-10-02 |
| 407488 | Global-buffer-overflow in CFX_Font::LoadGlyphPath | $1,000 | 2016-10-02 |
| 407964 | Heap-buffer-overflow in opj_t2_read_packet_header | $1,000 | 2016-10-02 |
| 407341 | Stack-buffer-overflow in cf2_hintmap_build | - | 2016-10-02 |
| 407339 | Vulnerability reported in elfutils | - | 2016-10-02 |
| 407477 | Heap-use-after-free in blink::EventHandlerRegistry::documentDetached | - | 2016-10-02 |
| 408141 | Heap-buffer-overflow in CPDF_LabCS::TranslateImageLine | $3,000 | 2016-10-02 |
| 407614 | Heap-buffer-overflow in TIFF_PredictLine | - | 2016-10-02 |
| 407476 | Heap-buffer-overflow in CJPX_Decoder::Init | - | 2016-10-02 |
| 406879 | Heap-use-after-free in cc::LayerTreeHost::RecreateUIResources | - | 2016-10-02 |
| 406868 | Heap-use-after-free in CPDF_Object::Release | $1,500 | 2016-10-02 |
| 406850 | Bad-cast to blink::AudioSummingJunction from invalid vptr;AudioContext.cpp:787:9 | - | 2016-10-02 |
| 406806 | Heap-buffer-overflow in CPDF_ICCBasedCS::GetRGB | - | 2016-10-02 |
| 406600 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | $500 | 2016-10-02 |
| 406895 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
| 406908 | Heap-buffer-overflow in CPDF_DIBSource::TranslateScanline24bpp | $1,000 | 2016-10-02 |
| 407235 | libcurl: Wildcard IP in cert's CN field can allow server spoof | - | 2016-10-02 |
| 406871 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in blink::InlineTextBox::constructTextRun | - | 2016-10-02 |
| 406591 | Heap-buffer-overflow in CPDF_SyntaxParser::SearchWord | $500 | 2016-10-02 |
| 406593 | Draw the image outside of the inline frame | $1,500 | 2016-10-02 |
| 415689 | Add an HSTS and key pin preload rule for chrome.com | - | 2016-10-02 |
| 415866 | Use-of-uninitialized-value in SkOpSegment::addTCoincident | $2,000 | 2016-10-02 |
| 415305 | UNKNOWN in blink::HRTFDatabaseLoader::load | - | 2016-10-02 |
| 415256 | SSLBlockingPage option mask isn't ORed | - | 2016-10-02 |
| 415012 | Heap-use-after-free in content::BrowserPlugin::~BrowserPlugin | - | 2016-10-02 |
| 415307 | Heap-buffer-overflow in chrome_pdf::PDFiumEngine::GetPageRect | $1,500 | 2016-10-02 |
| 415407 | ASSERTION FAILED: curr->isRenderInline(), UNKNOWN in blink::RenderInline::splitInlines | - | 2016-10-02 |
| 415306 | Heap-use-after-free in scoped_refptr<base::MessageLoopProxy>::operator= | - | 2016-10-02 |
| 414504 | Heap-use-after-free in opj_t1_decode_cblks | $1,000 | 2016-10-02 |
| 414310 | Heap-buffer-overflow in opj_jp2_apply_cdef | $1,000 | 2016-10-02 |
| 414182 | Heap-buffer-overflow in opj_t2_read_packet_header | - | 2016-10-02 |
| 414134 | Use-of-uninitialized-value in cricket::WebRtcVoiceMediaChannel::SetupSharedBweOnChannel | - | 2016-10-02 |
| 414606 | Heap-buffer-overflow in opj_v4dwt_interleave_h | $3,000 | 2016-10-02 |
| 414661 | Security: heap-use-after-free in CPDF_ShadingPattern::Clear() | - | 2016-10-02 |
| 414525 | Heap-buffer-overflow in opj_dwt_decode | $3,000 | 2016-10-02 |
| 414109 | Use-of-uninitialized-value in unsigned int blink::WidthIterator::advanceInternal<blink::SurrogatePairAwareTextIterator> | $1,000 | 2016-10-02 |
| 414100 | ASSERTION FAILED: node->isMediaControlElement(), UNKNOWN in blink::mediaControlElementType | - | 2016-10-02 |
| 414089 | Heap-double-free in j2k_read_ppm_v3 | $3,000 | 2016-10-02 |
| 414046 | Heap-use-after-free in CPDF_ImageObject::~CPDF_ImageObject | $2,000 | 2016-10-02 |
| 414036 | UNKNOWN in libc.so.6 | $2,000 | 2016-10-02 |
| 414124 | Security: TLS handshake and certificate signature forgery is possible using BleichenbacherĂąÂÂs Low-Exponent Attack due to faulty ASN.1 length decoding | $5,000 | 2016-10-02 |
| 414118 | Heap-use-after-free in content::ServiceWorkerControlleeRequestHandler::DidLookupRegistrationForMai | - | 2016-10-02 |
| 413850 | Use-of-uninitialized-value in chrome_pdf::PDFiumEngine::OnMouseMove | - | 2016-10-02 |
| 414026 | Do Not Cache Resources Retrieved Via Broken HTTPS in AppCache Or Service Worker | $500 | 2016-10-02 |
| 413744 | Heap-use-after-free in JavaObjectWeakGlobalRef::Assign | - | 2016-10-02 |
| 413743 | Heap-use-after-free in void cc::PreCalculateMetaInformation<cc::LayerImpl> | - | 2016-10-02 |
| 413706 | Security: Hotspot+appcache allows permanent sslstrip attack | - | 2016-10-02 |
| 413534 | Bad-cast to blink::AXMenuList from blink::AXList;AXMenuList.h:58:1 | - | 2016-10-02 |
| 413884 | Security: bug in nvmap Nvidia driver allows for privilege escalation. | - | 2016-10-02 |
| 413831 | Security: Issue with facetime:// and facetime-audio:// schemes | - | 2016-10-02 |
| 413375 | Negative-size-param in opj_t2_decode_packets | $1,000 | 2016-10-02 |
| 413316 | Use-after-free in blink::LocalDOMWindow::willDetachDocumentFromFrame | - | 2016-10-02 |
| 413094 | Security: ServiceWorker onfetch should not intercept Flash files or crossdomain.xml | - | 2016-10-02 |
| 413041 | Use-after-free in blink::ScriptWrappable::wrap | - | 2016-10-02 |
| 412790 | Use-of-uninitialized-value in FindSortableTop | - | 2016-10-02 |
| 413530 | Heap-use-after-free in blink::FrameView::scheduleRelayout | - | 2016-10-02 |
| 413447 | Heap-double-free in opj_tcd_code_block_dec_deallocate | - | 2016-10-02 |
| 413232 | Use-of-uninitialized-value in v8::internal::JSObject::UpdateAllocationSite | - | 2016-10-02 |
| 412457 | Heap-buffer-overflow in tt_face_get_location | - | 2016-10-02 |
| 411323 | Heap-use-after-free in content::RenderFrameImpl::Send | - | 2016-10-02 |
| 411320 | Heap-use-after-free in media::TimeDeltaInterpolator::GetInterpolatedTime | - | 2016-10-02 |
| 411318 | Heap-use-after-free in content::BufferedDataSource::ReadCallback | - | 2016-10-02 |
| 411735 | Use-after-free in blink::V8SVGFEMergeNodeElement::refObject | - | 2016-10-02 |
| 411329 | Use-of-uninitialized-value in SkColorTypeValidateAlphaType | - | 2016-10-02 |
| 411177 | Use-of-uninitialized-value in chrome_pdf::PageIndicator::OnTimerFired | - | 2016-10-02 |
| 411167 | Use-of-uninitialized-value in WebCore::RenderTableSection::dirtiedRows | - | 2016-10-02 |
| 411213 | Possible out of bounds access in BreakIterator class | - | 2016-10-02 |
| 411210 | CHECK failure in CHECK(start <= end) failed: ../../v8/src/heap/spaces.cc(1722) | - | 2016-10-02 |
| 422621 | Security: Cloud Print Connect XMPP connection leaks auth token to active network attacker | - | 2016-10-02 |
| 422492 | Heap-buffer-overflow in SkOpSegment::blindCoincident | $1,000 | 2016-10-02 |
| 421981 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-02 |
| 421817 | Security: handleAuthenticatorUrl to launch any activity from web page | $2,000 | 2016-10-02 |
| 421720 | Crash in RenderBlock::willBeDestroyed when removing from a map and destroying a continuation that has been already destroyed | - | 2016-10-02 |
| 422482 | Use-of-uninitialized-value in AvatarMenuBubbleView::LinkClicked | - | 2016-10-02 |
| 422374 | Google Account Sync auth token leaked to active network attacker who suppresses XMPP STARTTLS | - | 2016-10-02 |
| 421500 | Use-of-uninitialized-value in extensions::NativeMessageProcessHost::OnHostProcessLaunched | - | 2016-10-02 |
| 421332 | Security: Completely spoofable origin, including lock sign | $1,000 | 2016-10-02 |
| 421504 | Heap-use-after-free in blink::XMLHttpRequest::handleRequestError | - | 2016-10-02 |
| 421321 | Security: Use-after-free in blink::PageAnimator::serviceScriptedAnimations | - | 2016-10-02 |
| 421196 | Security: intra-object-overflow in third_party/pdfium/core/src/fpdfapi/fpdf_cmaps/fpdf_cmaps.cpp | - | 2016-10-02 |
| 421499 | Use-of-uninitialized-value in ucase_toupper_52 | - | 2016-10-02 |
| 421691 | Security: Accelerometer/gyroscope leak keystrokes and speech | - | 2016-10-02 |
| 421090 | Security: NaCl sandbox escape via DRAM "rowhammer" memory corruption | - | 2016-10-02 |
| 420450 | Heap-use-after-free in blink::RenderBlock::willBeDestroyed | - | 2016-10-02 |
| 421130 | Heap-use-after-free in blink::Element::setAttribute | - | 2016-10-02 |
| 421132 | Stack-buffer-underflow in SkDPoint::approximatelyEqual | $1,500 | 2016-10-02 |
| 419542 | Potential UAF in SSLErrorClassification during shutdown in tests | - | 2016-10-02 |
| 419774 | Heap-use-after-free in blink::HarfBuzzShaper::setGlyphPositionsForHarfBuzzRun | - | 2016-10-02 |
| 419428 | Uninit in featureWithPositiveInteger | - | 2016-10-02 |
| 419383 | Security: SOP Bypass of Data Exfiltration with CSS | $1,337 | 2016-10-02 |
| 419265 | ASSERTION FAILED: fontPlatformData, Heap-use-after-free in base::MessageLoop::PostTask | - | 2016-10-02 |
| 419060 | Heap-use-after-free in vorbis_decode_frame | $1,500 | 2016-10-02 |
| 419036 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 418976 | Heap-buffer-overflow in opj_tcd_get_decoded_tile_size | $500 | 2016-10-02 |
| 418881 | Heap-buffer-overflow in color_sycc_to_rgb | $1,000 | 2016-10-02 |
| 418585 | Heap-buffer-overflow in cff_get_glyph_name | - | 2016-10-02 |
| 419320 | Heap-use-after-free in CPDF_GeneralStateData::~CPDF_GeneralStateData | - | 2016-10-02 |
| 418402 | Security: Cross-Page and Cross-Domain Propagation of Click events on Mobile Devices | $1,000 | 2016-10-02 |
| 418381 | Heap-buffer-overflow in SkOpSegment::addCoinOutsides | $1,500 | 2016-10-02 |
| 418114 | Use-after-free in base::MessageLoop::DeleteSoonInternal | - | 2016-10-02 |
| 417841 | Mixed content resources (e.g. scripts) can be loaded using redirection | $1,000 | 2016-10-02 |
| 418582 | Heap-buffer-overflow in tt_cmap6_char_index | - | 2016-10-02 |
| 418161 | Heap-buffer-overflow in void SkMatrixConvolutionImageFilter::filterPixels<ClampPixelFetcher, false> | $2,000 | 2016-10-02 |
| 417210 | ThreadSanitizer v2 reports a heap-use-after-free in _get_bitmap_surface | - | 2016-10-02 |
| 417731 | Heap-use-after-free in blink::BaseMultipleFieldsDateAndTimeInputType::pickerIndicatorChooseValue | - | 2016-10-02 |
| 416526 | V8 slow/fast properties confusion | - | 2016-10-02 |
| 416696 | Container-overflow in chrome_pdf::PDFiumEngine::SelectFindResult | - | 2016-10-02 |
| 417329 | Security: code execution via bash environment variables | - | 2016-10-02 |
| 416528 | Out-of-bounds write in the browser via P2PHostMsg_Send IPC | - | 2016-10-02 |
| 416319 | Heap-use-after-free in CPDF_Color::~CPDF_Color | - | 2016-10-02 |
| 416323 | UNKNOWN in TcmapEncodingTable::GetSubtableAtIndex | $1,000 | 2016-10-02 |
| 416449 | Chrome exploit: V8 properties + P2PHostMsg_Send | $27,634 | 2016-10-02 |
| 416289 | Heap-buffer-overflow in GrBufferAllocPool::putBack | - | 2016-10-02 |
| 416362 | Potential UAF at WebCore::TimerBase::setNextFireTime | $2,000 | 2016-10-02 |
| 426890 | A vulnerability in run-mailcap can lead to code execution on Debian-based Linux distros with certain (nonstandard) desktop environments | $500 | 2016-10-02 |
| 426762 | Use-of-uninitialized-value in blink::Font::glyphDataAndPageForCharacter | $1,000 | 2016-10-02 |
| 426760 | Bad-cast to blink::ScriptWrappable from invalid vptr;ScriptWrappable.h:202:9 | - | 2016-10-02 |
| 426758 | Heap-use-after-free in blink::ScriptStreamer::notifyFinished | - | 2016-10-02 |
| 426757 | Use-after-free in blink::RenderSVGResourcePattern::patternForRenderer | - | 2016-10-02 |
| 425280 | Security: Flash Cross Domain Policy Bypass by Using File Upload and Redirection - only in Chrome | $2,000 | 2016-10-02 |
| 425263 | Security: wpa_supplicant CVE-2014-3686 | - | 2016-10-02 |
| 425153 | Heap-buffer-overflow in j2k_read_ppm_v3 | - | 2016-10-02 |
| 425152 | Heap-buffer-overflow in opj_stream_read_data | - | 2016-10-02 |
| 425151 | Heap-buffer-overflow in opj_tcd_init_decode_tile | - | 2016-10-02 |
| 425150 | Heap-use-after-free in opj_t1_decode_cblks | - | 2016-10-02 |
| 425040 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | - | 2016-10-02 |
| 425980 | UNKNOWN in media::container_names::DetermineContainer | $500 | 2016-10-02 |
| 425856 | Global-buffer-overflow in SkStrSearch | - | 2016-10-02 |
| 425585 | Use-of-uninitialized-value in v8::internal::Decoder<v8::internal::Simulator>::DecodeBranchSystemException | $2,500 | 2016-10-02 |
| 424998 | Heap-use-after-free in SkTypefaceCache::FindByProcAndRef | - | 2016-10-02 |
| 425001 | ASSERTION FAILED: repetitions > 0, UNKNOWN in blink::CSSPropertyParser::parseGridTrackRepeatFunction | - | 2016-10-02 |
| 424961 | Security: Local file access in plugins via chrome-extension protocol handler vulnerability | - | 2016-10-02 |
| 424957 | Use-of-uninitialized-value in blink::TransformationMatrix::rotate3d | - | 2016-10-02 |
| 424956 | Bad-cast to blink::RenderText from blink::RenderImage;RenderText.h:230:1 | - | 2016-10-02 |
| 425006 | Heap-use-after-free in blink::WebGLRenderingContextBase::printGLErrorToConsole | - | 2016-10-02 |
| 424999 | Use-of-uninitialized-value in aura::Window::GetNativeWindowProperty | - | 2016-10-02 |
| 424981 | Security: Flash Camera.copyToByteArray() memory corruption | - | 2016-10-02 |
| 424331 | UNKNOWN in opj_read_bytes_LE | $1,000 | 2016-10-02 |
| 424215 | Heap-buffer-overflow in WebRtcIsacfix_Decode | - | 2016-10-02 |
| 423899 | Security: UAF in CFX_DIBSource::GetWidth() | - | 2016-10-02 |
| 423891 | Bad-cast to blink::PODRedBlackTree<blink::PODInterval<int, blink::FloatingObject *> >::Node from invalid vptr;PODIntervalTree.h:175:33 | - | 2016-10-02 |
| 423703 | Security: Race condition in Flash workers may cause an exploitable double free | $7,500 | 2016-10-02 |
| 424619 | Reading from index -Infinity on typed array may cause random memory corruption (?) | - | 2016-10-02 |
| 424914 | ASSERTION FAILED: !current.value()->isInheritedValue(), Heap-use-after-free in blink::Element::detach | - | 2016-10-02 |
| 424216 | Heap-use-after-free in content::GpuChannelHost::Send | - | 2016-10-02 |
| 422765 | Heap-use-after-free in net::ClientCertStoreNSS::GetClientCertsOnWorkerThread | - | 2016-10-02 |
| 422693 | UNKNOWN in SuperBlitter::blitH | $2,000 | 2016-10-02 |
| 423084 | Chrome on iOS does not block active mixed content (scripts) | - | 2016-10-02 |
| 422824 | Heap-buffer-overflow in icu_52::RegexMatcher::MatchChunkAt | $4,000 | 2016-10-02 |
| 429779 | Heap-use-after-free in SetVolume | - | 2016-10-02 |
| 429922 | Security: A compromised renderer process could dismiss interstitial warnings it triggers | - | 2016-10-02 |
| 429740 | Heap-use-after-free in content::RTCPeerConnectionHandler::Observer::OnIceCandidate | - | 2016-10-02 |
| 429838 | Security: OpenSearch description files can be loaded from file:// URLs | $500 | 2016-10-02 |
| 429778 | UNKNOWN in webrtc::SdpSerialize | - | 2016-10-02 |
| 429626 | heap-buffer-overflow (read of size 1) at an unpronounceable function below SkScalerContext_FreeType_Base::generateGlyphImage | - | 2016-10-02 |
| 429679 | Heap-use-after-free in BookmarkContextMenuController::IsCommandIdEnabled | - | 2016-10-02 |
| 429585 | Heap-use-after-free in GetStats | - | 2016-10-02 |
| 429666 | Heap-use-after-free in blink::Node::setNeedsStyleRecalc | $2,000 | 2016-10-02 |
| 429542 | Security: file-to-file SOP bypass on Linux via /proc/self/fd/ | - | 2016-10-02 |
| 429276 | Security: Use after free in Flash (StageVideoAvailabilityEvent) can make bad things happen | $7,500 | 2016-10-02 |
| 429379 | Use-of-uninitialized-value in SkPath::arcTo | - | 2016-10-02 |
| 429201 | Heap-use-after-free in cc::PictureLayerTiling::UpdateEvictionCacheIfNeeded | - | 2016-10-02 |
| 429194 | Use-of-uninitialized-value in v8::internal::HOptimizedGraphBuilder::BuildBinaryOperation | - | 2016-10-02 |
| 429166 | Security: Heap Memory Corruption off-by-one (Overwrite 0x2C with 0x00) in ffmpeg function matroska_fix_ass_packet | - | 2016-10-02 |
| 429477 | Heap-use-after-free in TrackOnSuccess | - | 2016-10-02 |
| 429478 | Heap-use-after-free in blink::WebGLRenderingContextBase::printGLErrorToConsole | - | 2016-10-02 |
| 429244 | CSP Bypass on M39 | - | 2016-10-02 |
| 428829 | Heap-use-after-free in subtle::PrefMemberBase::VerifyPref | - | 2016-10-02 |
| 428828 | Heap-use-after-free in content::IndexedDBDatabase::RunVersionChangeTransaction | - | 2016-10-02 |
| 428800 | Heap-buffer-overflow in epoll_add | - | 2016-10-02 |
| 428789 | Heap-use-after-free in SkXfermodeImageFilter::~SkXfermodeImageFilter | - | 2016-10-02 |
| 428578 | Multiple Windows Kernel Crashes in Font Parsing | $6,500 | 2016-10-02 |
| 428561 | Heap-use-after-free in base::SupportsUserData::GetUserData | $1,500 | 2016-10-02 |
| 429139 | Heap-buffer-overflow in opj_t1_decode_cblks | - | 2016-10-02 |
| 429134 | Heap-buffer-overflow in CPDF_LabCS::GetDefaultValue | - | 2016-10-02 |
| 428557 | Stack-buffer-overflow in _XData32 | $2,000 | 2016-10-02 |
| 427397 | Heap-buffer-overflow in blink::CSPSourceList::parseHash | - | 2016-10-02 |
| 427272 | Security: UaF in FileSelectHelper::FileSelectedWithExtraInfo | $1,000 | 2016-10-02 |
| 427266 | Heap-use-after-free in matroska_read_seek | $2,000 | 2016-10-02 |
| 427249 | ASSERTION FAILED: m_pendingStylesheets > 0, Heap-use-after-free in blink::StyleEngine::clearResolver | $2,000 | 2016-10-02 |
| 427196 | console.log is breaking chrome://extensions | - | 2016-10-02 |
| 428137 | Heap-buffer-overflow in void v8::internal::String::WriteToFlat<unsigned short> | - | 2016-10-02 |
| 427303 | UNKNOWN in blink::HRTFDatabaseLoader::load | - | 2016-10-02 |
| 427108 | Heap-use-after-free in blink::PendingScript::stopWatchingForLoad | $2,000 | 2016-10-02 |
| 436022 | Security: Race condition in workers may cause an exploitable double free by abusing bytearray.compress() | $7,500 | 2016-10-02 |
| 435825 | UNKNOWN in v8::internal::String::length | - | 2016-10-02 |
| 435815 | Bad-cast to blink::RenderTable from blink::RenderBlockFlow;RenderTable.h:366:1 | - | 2016-10-02 |
| 435567 | Use-of-uninitialized-value in void v8::internal::ScavengingVisitor< | - | 2016-10-02 |
| 435514 | Heap-use-after-free in rdft_calc_c | - | 2016-10-02 |
| 435383 | Heap-based buffer overflow in Flash PCRE regex engine | $3,000 | 2016-10-02 |
| 435073 | CHECK failure in CHECK(p->IsSmi()) failed: ../../v8/src/objects-debug.cc(32) | $3,500 | 2016-10-02 |
| 435880 | Heap-buffer-overflow in std::less<std::string>::operator | $4,500 | 2016-10-02 |
| 434970 | Heap-use-after-free in blink::ScopedStyleResolver::collectFeaturesTo | - | 2016-10-02 |
| 434964 | Chrome's uninstaller launches IE w/ an unquoted path to iexplore.exe | - | 2016-10-02 |
| 434733 | Use-after-free in blink::ResourceFetcher::didFinishLoading | - | 2016-10-02 |
| 434732 | ASSERTION FAILED: !m_deletionHasBegun, UNKNOWN in blink::Node::remove | - | 2016-10-02 |
| 434972 | Heap-use-after-free in webrtc::internal::SynchronousMethodCall::Invoke | - | 2016-10-02 |
| 434723 | Heap-use-after-free in content::MediaStreamTrackMetricsObserver::SendLifetimeMessages | - | 2016-10-02 |
| 434569 | Security: Heap-use-after-free in SupportsUserData::GetUserData | $500 | 2016-10-02 |
| 434728 | Use-after-free in blink::RenderLayer::updatePagination | - | 2016-10-02 |
| 434499 | Security: Hera color from previous page remains on interstitial load | - | 2016-10-02 |
| 433866 | Use-of-uninitialized-value in getNextNormalizedChar | $1,000 | 2016-10-02 |
| 433860 | Use-after-free in blink::AXObject::document | - | 2016-10-02 |
| 434136 | WebAudio render that coincides with GC graph mutation can cause snap | $4,000 | 2016-10-02 |
| 433359 | UNKNOWN in void SkMatrixConvolutionImageFilter::filterPixels<UncheckedPixelFetcher, fa | - | 2016-10-02 |
| 433357 | Use-after-free in blink::HTMLPlugInElement::renderPartForJSBindings | - | 2016-10-02 |
| 433078 | Security: OOB read in dhcpcd | - | 2016-10-02 |
| 433445 | UNKNOWN in v8::internal::FixedArray::get | $1,500 | 2016-10-02 |
| 433170 | Media permission not displayed in PageInfo | - | 2016-10-02 |
| 432209 | Heap-buffer-overflow in icu_52::RegexMatcher::MatchChunkAt | - | 2016-10-02 |
| 432575 | ASSERTION FAILED: offset + length <= m_length, UNKNOWN in blink::InlineTextBox::constructTextRun | - | 2016-10-02 |
| 432572 | Heap-use-after-free in std::unordered_map<int,enum gfx::GpuMemoryBufferType,std::hash<int>,std::eq | - | 2016-10-02 |
| 431504 | Security: Cookie injection by Proxy with 407 response | $500 | 2016-10-02 |
| 431288 | Heap-buffer-overflow in opj_tcd_init_decode_tile | $500 | 2016-10-02 |
| 431860 | Heap-use-after-free in v8::internal::Isolate::counters | - | 2016-10-02 |
| 431602 | UNKNOWN in v8::internal::RootMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
| 431603 | ASSERTION FAILED: to <= m_run.length(), UNKNOWN in blink::HarfBuzzShaper::setDrawRange | - | 2016-10-02 |
| 430787 | UNKNOWN in v8::internal::HeapObjectIterator::FromCurrentPage | - | 2016-10-02 |
| 430786 | Heap-use-after-free in webrtc::PeerConnection::OnAddDataChannel | - | 2016-10-02 |
| 430630 | Security: Content settings (e.g. disallow images/javascript) not honored on frames created while interstitial is showing | - | 2016-10-02 |
| 430925 | Heap-use-after-free in webrtc::PeerConnection::OnSessionStateChange | - | 2016-10-02 |
| 430928 | Heap-use-after-free in webrtc::RemoteAudioSource::SetVolume | - | 2016-10-02 |
| 430891 | Heap-buffer-overflow in opj_j2k_tcp_destroy | $2,000 | 2016-10-02 |
| 430533 | Heap-use-after-free in cc::ResourceProvider::ScopedWriteLockGpuMemoryBuffer::GetGpuMemoryBuffer | - | 2016-10-02 |
| 430353 | UNKNOWN in icu_52::RegexMatcher::MatchChunkAt | $5,000 | 2016-10-02 |
| 430351 | Heap-buffer-overflow in blink::CSPSourceList::parseNonce | - | 2016-10-02 |
| 430588 | Security: backport seccomp-tsync | - | 2016-10-02 |
| 430566 | Heap-buffer-overflow in opj_jp2_apply_pclr | $500 | 2016-10-02 |
| 442710 | Stack-buffer-overflow in v8::internal::MarkCompactCollector::SweepInParallel | $3,000 | 2016-10-02 |
| 442756 | Security: Denial of service attack against third-parties using web sockets | - | 2016-10-02 |
| 442585 | Security: Flash Player RegExp Object Integer Signedness Error | $4,000 | 2016-10-02 |
| 442454 | Use-after-free in blink::RenderLayer::invalidatePaintForBlockSelectionGaps | - | 2016-10-02 |
| 442806 | Heap-use-after-free in blink::TreeScopeEventContext::ensureEventPath | $3,000 | 2016-10-02 |
| 442670 | Security: NPAPI windowless flash can listen system input events (bypassing browser) | - | 2016-10-02 |
| 441834 | Chromoting host must call CloseClipboard() with anonymous access token | - | 2016-10-02 |
| 442121 | ASSERTION FAILED: !value || (value->isValueList()) | $2,000 | 2016-10-02 |
| 440694 | Security: Windows Token Hardening - Ensure Opening of Named Pipes Specifies Anonymous Impersonation Level | - | 2016-10-02 |
| 440834 | Use-after-free in blink::HTMLImageFallbackHelper::createAltTextShadowTree | - | 2016-10-02 |
| 440833 | Heap-buffer-underflow in blink::AXRenderObject::computeAccessibilityIsIgnored | - | 2016-10-02 |
| 440990 | Security: module locking can be disable after boot in verified mode | - | 2016-10-02 |
| 440693 | Security: Windows Token Hardening - Impersonate Anonymous Token Across CloseClipboard Calls | - | 2016-10-02 |
| 440692 | Security: Windows Token Hardening - Modify Broker Process Token IL Policy | - | 2016-10-02 |
| 440572 | Security: Circumvent Safe Browsing with data urls | - | 2016-10-02 |
| 441095 | Heap-use-after-free in blink::ResourceResponse::~ResourceResponse | - | 2016-10-02 |
| 440836 | Bad-cast to blink::Element from blink::CDATASection;Element.h:651:1 | - | 2016-10-02 |
| 440268 | Security: Encoded script URL can get around the path restriction | - | 2016-10-02 |
| 439992 | Use-of-uninitialized-value in icu_52::RegexMatcher::findUsingChunk | - | 2016-10-02 |
| 439877 | Security: HTML Imports ignores Content-Type and Content-Disposition headers. | - | 2016-10-02 |
| 440435 | Heap-use-after-free in base::MessageLoop::PostTask | - | 2016-10-02 |
| 439319 | Use-after-free in blink::TreeScope::comparePosition | - | 2016-10-02 |
| 438638 | Use-after-free in blink::AXSpinButton::elementRect | - | 2016-10-02 |
| 438364 | Heap-use-after-free in blink::VectorMath::vadd | - | 2016-10-02 |
| 438363 | UNKNOWN in avio_read | - | 2016-10-02 |
| 438157 | Windows Sandbox: Chromium's FILES_ALLOW_READONLY policy can be bypassed to create empty files or delete the contents of existing files | - | 2016-10-02 |
| 437960 | chrome.identity.getAuthToken leaks master-token and gives attacker a full control over a two-factor-protected Google account | - | 2016-10-02 |
| 438365 | Heap-use-after-free in views::X11WholeScreenMoveLoop::RunMoveLoop | - | 2016-10-02 |
| 437681 | ASSERTION FAILED: !result, Heap-use-after-free in blink::DirectConvolver::process | - | 2016-10-02 |
| 437655 | Heap-use-after-free in vp9_setup_mask | - | 2016-10-02 |
| 437636 | Bad-cast to blink::AudioNode from invalid vptr;AudioNode.cpp:401:13 | - | 2016-10-02 |
| 437472 | Heap-buffer-overflow in android::BlobCache::flatten | - | 2016-10-02 |
| 437464 | Use-of-uninitialized-value in udev_monitor_enable_receiving | - | 2016-10-02 |
| 437682 | Heap-use-after-free in blink::AudioChannel::zero | - | 2016-10-02 |
| 437651 | Heap-use-after-free in void blink::ImageDecodingStore::insertCacheInternal<blink::ImageDecodingSto | $3,000 | 2016-10-02 |
| 437399 | Heap-buffer-overflow in blink::BidiResolver<blink::InlineIterator, blink::BidiRun>::applyL1Rule | $500 | 2016-10-02 |
| 436520 | Heap-buffer-overflow in content::RtcDataChannelHandler::OnStateChange | - | 2016-10-02 |
| 437458 | Heap-buffer-overflow in blink::Character::expansionOpportunityCount | - | 2016-10-02 |
| 437441 | Security: Use After Free in Flash MessageChannel.send() | $5,000 | 2016-10-02 |
| 447773 | ASSERTION FAILED: !node || isElementOfType<const T>(*node) | - | 2016-10-02 |
| 447644 | Use-of-uninitialized-value in blink::DocumentAnimations::updateAnimationTimingIfNeeded | - | 2016-10-02 |
| 447567 | UNKNOWN in v8::internal::JSFunction::shared | - | 2016-10-02 |
| 446672 | UNKNOWN in libc.so.6 | - | 2016-10-02 |
| 446538 | File download .dotfiles sanitization fails when the file starts with a space | - | 2016-10-02 |
| 446537 | Add "Show hidden files" to gear menu | - | 2016-10-02 |
| 447664 | ASSERTION FAILED: !value || (value->isPrimitiveValue()) | - | 2016-10-02 |
| 446164 | Security: Integer Overflow in WebGL | $3,000 | 2016-10-02 |
| 446078 | Persistent DoS attack on storage space on Chrome OS | - | 2016-10-02 |
| 446076 | ASSERTION FAILED: !m_deletionHasBegun | - | 2016-10-02 |
| 446037 | Use-after-free in blink::RenderQuote::attachQuote | - | 2016-10-02 |
| 446033 | UNKNOWN in Read_CVT | $1,000 | 2016-10-02 |
| 446032 | Security: OOM situation can result in heap buffer overflow in CFX_BinaryBuf (pdfium) | $3,000 | 2016-10-02 |
| 446459 | Security: Proxy credential leak: WebSockets send proxy headers to destination server | - | 2016-10-02 |
| 445831 | UNKNOWN in SA8_alpha_D32_nofilter_DX | - | 2016-10-02 |
| 445808 | Stack-buffer-overflow in SkPackBits::Unpack8 | $2,000 | 2016-10-02 |
| 445809 | Heap-buffer-overflow in SkBitmap::ReadRawPixels | $5,000 | 2016-10-02 |
| 445902 | Use-of-uninitialized-value in GrBitmapTextGeoProc::getGLProcessorKey | - | 2016-10-02 |
| 445807 | Global-buffer-overflow in SkGradientShaderBase::SkGradientShaderBase | $5,000 | 2016-10-02 |
| 445810 | Heap-buffer-overflow in SkImageFilter::Common::unflatten | $5,000 | 2016-10-02 |
| 445741 | Heap-use-after-free in base::MessageLoop::DeleteSoonInternal | - | 2016-10-02 |
| 445747 | Use-after-free in std::_Tree<std::_Tmap_traits<base::FilePath,bool,std::less<base::FilePath>, | - | 2016-10-02 |
| 445653 | Security: Potential bugs/vulnerabilities in GPU code | - | 2016-10-02 |
| 445638 | ASSERT_NOT_REACHED in blink::LengthStyleInterpolation::interpolableValueToLength | - | 2016-10-02 |
| 445332 | ASSERTION FAILED: !value || (value->isPrimitiveValue()) | $1,500 | 2016-10-02 |
| 445305 | Use-of-uninitialized-value in blink::MediaControls::shouldHideMediaControls | - | 2016-10-02 |
| 445304 | ASSERTION FAILED: obj->isRenderInline() || obj == this | - | 2016-10-02 |
| 445679 | Memory error when importing bogus EC private key from PKCS8 into BoringSSL | - | 2016-10-02 |
| 445303 | Heap-buffer-overflow in void blink::SearchBuffer::append<unsigned char> | - | 2016-10-02 |
| 445285 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | $2,000 | 2016-10-02 |
| 445267 | UNKNOWN in v8::internal::Invoke | $3,500 | 2016-10-02 |
| 445107 | Use of unitialized value in toDataUrl / jpeg encoding path | - | 2016-10-02 |
| 444957 | Heap-use-after-free in OpenPDFInReaderBubbleView::ButtonPressed | $500 | 2016-10-02 |
| 444927 | Security: Inherited designMode and cross-window drag-n-drop allow to modify a cross-origin iframe's DOM | $3,000 | 2016-10-02 |
| 444717 | Invalid RenderFrameHost pointer is passed to WebNavigationTabObserver::DidOpenRequestedURL in test WebNavigationApiTest.CrossProcess | - | 2016-10-02 |
| 444707 | Use-of-uninitialized-value in unsigned int blink::SimpleShaper::advanceInternal<blink::SurrogatePairAware | $1,000 | 2016-10-02 |
| 444695 | UNKNOWN in v8::internal::Invoke | $3,500 | 2016-10-02 |
| 444681 | Use-after-poison in v8::internal::compiler::InstructionSelector::InitializeCallBuffer | $3,500 | 2016-10-02 |
| 444573 | Use-of-uninitialized-value in ucnv_io_getConverterName_52 | $1,000 | 2016-10-02 |
| 444546 | Heap/Stack Memory Info Leak - FFMPEG libavformat\mov.c | $2,000 | 2016-10-02 |
| 444539 | Heap Corruption - FFMPEG libavformat\mov.c - Use-After-Free/Double Free | $4,000 | 2016-10-02 |
| 444198 | Security: ViewHostMsg_RunFileChooser IPC allows renderer control over absolute path | - | 2016-10-02 |
| 444084 | UNKNOWN in v8::internal::IC::raw_target | - | 2016-10-02 |
| 443744 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 443675 | Heap-use-after-free in blink::TreeScope::clearScopedStyleResolver | - | 2016-10-02 |
| 444522 | Heap-buffer-overflow in ff_mov_read_stsd_entries | $5,000 | 2016-10-02 |
| 443356 | Security: No process swap between file:// and data: URLs | - | 2016-10-02 |
| 443333 | Security: tracking bug for ffmpeg H.264 fixes | - | 2016-10-02 |
| 443115 | Heap-use-after-free in blink::PendingScript::stopWatchingForLoad | $2,000 | 2016-10-02 |
| 443017 | Heap-use-after-free in blink::ScopedStyleResolver::collectFeaturesTo | $3,000 | 2016-10-02 |
| 443476 | Use-after-free in WTF::VectorDestructor<1,blink::Canvas2DLayerBridge::MailboxInfo>::destruct | - | 2016-10-02 |
| 443274 | memory access bug in harfbuzz when a carefully crafted font is fed | - | 2016-10-02 |
| 451918 | ASSERTION FAILED: it != m_customElementBindings.end() | - | 2016-10-02 |
| 451773 | ASSERTION FAILED: !object || (object->isTableCell()) | - | 2016-10-02 |
| 451753 | UNKNOWN in DestroyPropertySheetPage+0x4e | - | 2016-10-02 |
| 451685 | Use-after-poison in blink::callTransactionErrorCallback | - | 2016-10-02 |
| 451684 | ASSERTION FAILED: node->isMediaControlElement() | - | 2016-10-02 |
| 451770 | UNKNOWN in v8::internal::SharedFunctionInfo::code | - | 2016-10-02 |
| 451799 | Heap overflow and integer overflow in ICU library | $500 | 2016-10-02 |
| 451755 | UNKNOWN in content::WebContentsImpl::OnOpenColorChooser | - | 2016-10-02 |
| 451058 | Use-of-uninitialized-value in blink::HarfBuzzShaper::HarfBuzzShaper | - | 2016-10-02 |
| 450844 | Heap-buffer-overflow in opj_dwt_decode_1 | $1,000 | 2016-10-02 |
| 450654 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
| 451059 | Heap-use-after-free in blink::RenderObject::setNeedsLayout | - | 2016-10-02 |
| 450939 | Negative-size-param in vp9_dec_setup_mi | $1,000 | 2016-10-02 |
| 451509 | Heap-buffer-overflow in Pickle::WriteData | - | 2016-10-02 |
| 451456 | Heap-use-after-free in content::GpuChannelHost::DestroyChannel() | $500 | 2016-10-02 |
| 450389 | Use-of-uninitialized-value in SkPreMultiplyARGB | $1,000 | 2016-10-02 |
| 450198 | Adobe Flash Player Out-of-Bound Access Vulnerability | $2,000 | 2016-10-02 |
| 450096 | Heap-use-after-free in base::internal::DiscardableMemoryShmem::AllocateAndAcquireLock | - | 2016-10-02 |
| 450653 | UNKNOWN in blink::InlineTextBox::isLineBreak | - | 2016-10-02 |
| 450642 | UNKNOWN in v8::internal::Code::deoptimization_data | - | 2016-10-02 |
| 450391 | Security: aarch64 seccomp lacks ability to redirect syscalls | - | 2016-10-02 |
| 450038 | Heap-buffer-overflow in blink::BidiResolver<blink::InlineIterator, blink::BidiRun>::applyL1Rule | - | 2016-10-02 |
| 449845 | Use-of-uninitialized-value in CFX_ByteString::FormatInteger | - | 2016-10-02 |
| 449829 | Security: Illegal domain name resolving using leading dot creating unexpected behaviour/URL Bar Spoofing | $1,000 | 2016-10-02 |
| 449777 | UNKNOWN in content::WebContentsImpl::OnOpenColorChooser | - | 2016-10-02 |
| 449739 | Security: Heap-use-after-free SpeechRecognitionDispatcher | $1,000 | 2016-10-02 |
| 449610 | ZDI-CAN-2662: Google Chrome V8EventListenerList::findOrCreateWrapper Type Confusion Remote Code Execution Vulnerability | - | 2016-10-02 |
| 449893 | Heap-buffer-overflow in media::AudioBus::SwapChannels | - | 2016-10-02 |
| 449958 | Heap-buffer-overflow in media::CopyPlane | $2,000 | 2016-10-02 |
| 449049 | Heap-use-after-free in blink::WorkerSharedTimer::setFireInterval | - | 2016-10-02 |
| 449047 | Use-after-free in blink::Canvas2DLayerBridge::mailboxReleased | - | 2016-10-02 |
| 449045 | Heap-use-after-free in blink::NavigationScheduler::shouldScheduleNavigation | - | 2016-10-02 |
| 448798 | Use-of-uninitialized-value in IPC::ChannelPosix::ProcessOutgoingMessages | - | 2016-10-02 |
| 449574 | Heap-use-after-free in extensions::MimeHandlerViewContainer::OnMessageReceived | - | 2016-10-02 |
| 449291 | Global-buffer-overflow in v8::internal::MarkCompactCollector::EmptyMarkingDeque | - | 2016-10-02 |
| 448423 | Heap-buffer-overflow in SkData::NewUninitialized | $5,000 | 2016-10-02 |
| 448314 | Heap-use-after-free in blink::V8PerContextData::constructorForTypeSlowCase | $3,000 | 2016-10-02 |
| 448189 | Wild read in aura::GetDeviceScaleFactorFromDisplay | - | 2016-10-02 |
| 448102 | Bad-cast to v8::internal::OFStreamBase from base class subobject at offset 8;ostreams.cc:27:37 | - | 2016-10-02 |
| 448082 | Heap-use-after-free in content::ServiceWorkerScriptCacheMap::NotifyFinishedCaching | $2,500 | 2016-10-02 |
| 448081 | Heap-use-after-free in blink::FrameLoaderClientImpl::allowScript | - | 2016-10-02 |
| 448428 | Heap-use-after-free in /usr/lib/libstdc++.6.dylib+0x2dfc9 | - | 2016-10-02 |
| 448299 | Heap-buffer-overflow in sk_memset32_SSE2 | - | 2016-10-02 |
| 448056 | UNKNOWN in content::WebContentsImpl::OnDidStartLoading | - | 2016-10-02 |
| 448006 | Heap-use-after-free in blink::Node::compareDocumentPosition | $3,000 | 2016-10-02 |
| 447976 | Heap-use-after-free in blink::ScopedStyleResolver::collectMatchingAuthorRules | $3,000 | 2016-10-02 |
| 447906 | Heap-use-after-free in blink::DateTimeEditElement::~DateTimeEditElement | $5,000 | 2016-10-02 |
| 447889 | Global-buffer-overflow in hb_indic_get_categories | - | 2016-10-02 |
| 447860 | global-buffer-overflow at vp56_rac_get_prob_branchy | $500 | 2016-10-02 |
| 448057 | Use-of-uninitialized-value in extract_image_data | - | 2016-10-02 |
| 448061 | ASSERTION FAILED: !object || (object->isText()) | - | 2016-10-02 |
| 448008 | Select/option website clickjacking | - | 2016-10-02 |
| 447852 | Vulnerability reported in dev-libs/openssl | - | 2016-10-02 |
| 458777 | Heap-use-after-free in blink::Frame::host | - | 2016-10-02 |
| 458776 | Heap-use-after-free in blink::WebPluginContainerImpl::scriptableObject | - | 2016-10-02 |
| 458868 | Heap-use-after-free in content::ChildThreadImpl::ShutdownThread | - | 2016-10-02 |
| 458861 | Heap-buffer-overflow in chromium_ijg_jpeg_idct_islow | - | 2016-10-02 |
| 457480 | Heap-buffer-overflow in opj_dwt_decode | $3,000 | 2016-10-02 |
| 458184 | Use-after-free in blink::LayoutObject::isRooted | - | 2016-10-02 |
| 458024 | [qcms] security - stack buffer overread in lut_inverse_interp16 | - | 2016-10-02 |
| 457680 | Security: Flash AS2 Use After Free in DisplacementMapFilter.mapBitmap | $5,000 | 2016-10-02 |
| 457583 | Security: Flash AS2 ConvolutionFilter Uninitialized Memory Leak | $4,000 | 2016-10-02 |
| 457493 | Heap-double-free in j2k_read_ppm_v3 | $2,000 | 2016-10-02 |
| 458026 | [qcms] security - heap info leak in qcms | - | 2016-10-02 |
| 458474 | Heap-use-after-free in net::FileStream::Context::ReadAsyncResult | - | 2016-10-02 |
| 458191 | Heap-use-after-free in blink::HTMLImportTreeRoot::recalcTimerFired | - | 2016-10-02 |
| 456920 | Heap-use-after-free in base::ElapsedTimer::Elapsed | - | 2016-10-02 |
| 456841 | Security: Extensions can silently debug (run code) in ANY tab and escape the sandbox | $1,000 | 2016-10-02 |
| 456828 | Security: heap-buffer-overflow in SkGradientShaderBase::SkGradientShaderBase | $5,000 | 2016-10-02 |
| 457278 | Security: Flash AS2 Use After Free in TextField.filters | $5,000 | 2016-10-02 |
| 456635 | Heap-use-after-free in blink::Node::compareDocumentPosition | - | 2016-10-02 |
| 456532 | Heap-use-after-free in blink::UserMediaRequest::start | - | 2016-10-02 |
| 456516 | Security: MidiHostMsg_SendData vector OOB on Android | $7,500 | 2016-10-02 |
| 456391 | Don't supply invalid hostnames to the DNS resolver | - | 2016-10-02 |
| 456206 | Heap-buffer-overflow in parse_encoding | $500 | 2016-10-02 |
| 456192 | Possibly invalid type cast in blink::V8LazyEventListener::prepareListenerObject | $3,000 | 2016-10-02 |
| 456636 | Use-of-uninitialized-value in blink::CustomElementUpgradeCandidateMap::~CustomElementUpgradeCandidateMap | - | 2016-10-02 |
| 456101 | Security: Race condition in Flash workers may cause an exploitable double free by abusing bytearray.writeObject | $7,500 | 2016-10-02 |
| 456059 | Heap-use-after-free in blink::PendingScript::stopWatchingForLoad | $3,000 | 2016-10-02 |
| 455964 | Security: NaCl process are not marked non-dumpable. | - | 2016-10-02 |
| 455953 | Security: file:// origins can use webkitRequestFullscreen and requestPointerLock without a prompt | - | 2016-10-02 |
| 455857 | Google Chrome SpeechRecognitionClient Use-After-Free Remote Code Execution Vulnerability | - | 2016-10-02 |
| 455839 | Security: NaCl processes should have an address space usage limit | - | 2016-10-02 |
| 455994 | double free at content::RenderFrameImpl::~RenderFrameImpl | - | 2016-10-02 |
| 455428 | Password is read out in the 'connect to corp network' window | - | 2016-10-02 |
| 455368 | UNKNOWN in blink::SQLStatementBackend::execute | $2,500 | 2016-10-02 |
| 455215 | Security: HSTS not applied to WebSocket | $500 | 2016-10-02 |
| 454426 | Use-of-uninitialized-value in FT_RoundFix | - | 2016-10-02 |
| 454280 | Use-of-uninitialized-value in CPDF_Function::Call | - | 2016-10-02 |
| 454278 | Use-after-free in media::CdmSessionAdapter::Initialize | - | 2016-10-02 |
| 454268 | Heap-buffer-overflow in PPP_GetInterface | - | 2016-10-02 |
| 454231 | Heap Use After Free @blink::BaseMultipleFieldsDateAndTimeInputType::readonlyAttributeChanged | $2,000 | 2016-10-02 |
| 455735 | UNKNOWN in blink::WebSpeechSynthesisVoice::operator | $2,000 | 2016-10-02 |
| 455363 | Heap-buffer-overflow in ps_table_add | - | 2016-10-02 |
| 453994 | Security: GaiaAuthExtension is too powerful and should validate parameter | - | 2016-10-02 |
| 452794 | Heap-use-after-free in CPDFSDK_Widget::GetMixXFAWidget | - | 2016-10-02 |
| 453553 | SIGSEGV in opj_j2k_update_image_data via pdfium_test | - | 2016-10-02 |
| 453279 | Heap-use-after-free in blink::MutationObserverRegistration::unregister | $3,000 | 2016-10-02 |
| 453209 | Use-after-poison in blink::ThreadHeap::allocate+0x58 | - | 2016-10-02 |
| 453126 | Undefined behavior (bad virtual call) in net/socket/ssl_client_socket_pool.cc | - | 2016-10-02 |
| 454153 | Global-buffer-overflow in blink::AXRenderObject::text | - | 2016-10-02 |
| 452793 | Heap-use-after-free in FT_Stream_ReleaseFrame | - | 2016-10-02 |
| 454157 | Use-of-uninitialized-value in void v8::internal::ScavengingVisitor< | - | 2016-10-02 |
| 453979 | Security: UXSS in V8 | - | 2016-10-02 |
| 452135 | ASSERTION FAILED: !m_renderGrid.gridIsDirty() in blink::GridPainter::paintChildren | - | 2016-10-02 |
| 452059 | Copy-Paste XSS (ODT to contenteditable) | - | 2016-10-02 |
| 452638 | Heap-use-after-free in content::RenderFrameImpl::DecidePolicyForNavigation | - | 2016-10-02 |
| 452455 | Heap-buffer-overflow in CPDF_SampledFunc::v_Call | - | 2016-10-02 |
| 464409 | Update net-misc/radsecproxy to 1.6.6 | - | 2016-10-02 |
| 464391 | Heap-use-after-free in base::internal::CallbackBase::Reset | - | 2016-10-02 |
| 464463 | Use-of-uninitialized-value in content::BrowserMessageFilter::Send | - | 2016-10-02 |
| 464594 | Use-of-uninitialized-value in content::BrowserMessageFilter::Send | - | 2016-10-02 |
| 463958 | Heap-use-after-free in xmlSwitchEncoding | $1,000 | 2016-10-02 |
| 463920 | Heap-use-after-free in SuperBlitter::blitH | - | 2016-10-02 |
| 463599 | Heap-buffer-overflow in blink::WebString::fromUTF8 | $1,000 | 2016-10-02 |
| 462843 | Security: UXSS in AuthenticatorHelper | $7,500 | 2016-10-02 |
| 462300 | Heap-buffer-overflow in resize_context_buffers | - | 2016-10-02 |
| 461936 | Heap-use-after-free in gcm::GCMClientImpl::OnRegisterCompleted | - | 2016-10-02 |
| 461858 | Chrome allows "Always open files of this type" to be used with executables | $500 | 2016-10-02 |
| 462319 | Heap-use-after-free in gcm::SocketInputStream::Refresh | - | 2016-10-02 |
| 461474 | UNKNOWN in bool blink::outputRows< | - | 2016-10-02 |
| 461191 | Security: UNKNOWN in RenderFrameImpl::OnMessageReceived | $3,000 | 2016-10-02 |
| 461481 | Security: HSTS bypass | $1,000 | 2016-10-02 |
| 460939 | Heap-use-after-free in content::GLHelper::CopyTextureToImpl::FinishRequest | - | 2016-10-02 |
| 460938 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
| 460937 | UNKNOWN in v8::internal::IC::SetTargetAtAddress | - | 2016-10-02 |
| 460936 | Use-of-uninitialized-value in FT_DivFix | - | 2016-10-02 |
| 460917 | OOB write in v8 due to elements kind confusion | $500 | 2016-10-02 |
| 461472 | Heap-use-after-free in blink::PopupMenuImpl::didClosePopup | - | 2016-10-02 |
| 460751 | Use-after-free in blink::ColorInputType::didEndChooser | - | 2016-10-02 |
| 460426 | Add RELEASE_ASSERTs to ScriptRunner to crash in a more controlled way? | - | 2016-10-02 |
| 460391 | Search query highlights the scheme of the search term and displays like a URL | - | 2016-10-02 |
| 460145 | Unsafe %GeneratorFuntion% intrinsic cannot be denied | - | 2016-10-02 |
| 459898 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | - | 2016-10-02 |
| 459897 | Use-of-uninitialized-value in SkConic::computeQuadPOW2 | - | 2016-10-02 |
| 460752 | Heap-use-after-free in blink::Document::didChangeVisibilityState | - | 2016-10-02 |
| 460431 | Regression: Chrome crashes when "No thanks" link is dropped in any text-boxes on Chrome sign-in page. | - | 2016-10-02 |
| 459637 | Use-of-uninitialized-value in v8::internal::compiler::Schedule::block | - | 2016-10-02 |
| 459633 | Use-after-poison in v8::internal::compiler::Node::Input::Update | - | 2016-10-02 |
| 459632 | Bad parameters to __sanitizer_annotate_contiguous_container in blink::EventListenerMap::EventListenerMap | - | 2016-10-02 |
| 459564 | XSS in chrome://webrtc-internals/ | - | 2016-10-02 |
| 459533 | Heap-use-after-free in blink::LayoutLayerModelObject::hasSelfPaintingLayer | $2,000 | 2016-10-02 |
| 459483 | Use-of-uninitialized-value in sha1_final | - | 2016-10-02 |
| 459445 | Security: Url Bar Spoofing using the redirections at shopping.paypal.com | - | 2016-10-02 |
| 459862 | Heap-use-after-free in blink::VectorMath::zvmul | - | 2016-10-02 |
| 458871 | Use-of-uninitialized-value in blink::RenderView::setSelection | - | 2016-10-02 |
| 459215 | Security: pdfium - write past end of heap buffer when parsing invalid JPEG2000 image | $3,000 | 2016-10-02 |
| 459114 | Heap-use-after-free in get_lowest_part_y | - | 2016-10-02 |
| 459043 | Chrome_Mac: Crash Report - blink::HarfBuzzShaper::setGlyphPositionsForHarfBuzzRun | - | 2016-10-02 |
| 458876 | Use-of-uninitialized-value in v8::internal::compiler::Schedule::block | $1,000 | 2016-10-02 |
| 458875 | Global-buffer-overflow in cff_parse_real | - | 2016-10-02 |
| 458873 | Heap-buffer-overflow in bloat_quad | - | 2016-10-02 |
| 459115 | Heap-use-after-free in content::MessagePortService::UpdateMessagePort | - | 2016-10-02 |
| 459239 | Heap-use-after-free in base::ElapsedTimer::Elapsed | - | 2016-10-02 |
| 458870 | Heap-use-after-free in blink::TreeScopeStyleSheetCollection::analyzeStyleSheetChange | - | 2016-10-02 |
| 458869 | UNKNOWN in TLine::GetMappedCharsInRange | - | 2016-10-02 |
| 469395 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 469305 | Update sqlite to uptake http://www.sqlite.org/src/info/ceebcdcaf1acf409 | - | 2016-10-02 |
| 469247 | Use-of-uninitialized-value in blink::TransformationMatrix::blend | - | 2016-10-02 |
| 469244 | Stack-buffer-overflow in CFX_WideString::FormatV | $1,000 | 2016-10-02 |
| 469152 | P2PSocketDispatcherHost UaF | - | 2016-10-02 |
| 469151 | GamepadProvider infoleak | - | 2016-10-02 |
| 469148 | UNKNOWN in v8::internal::ExternalUint32Array::SetValue | - | 2016-10-02 |
| 469082 | Security: sqlite bad ptr access | - | 2016-10-02 |
| 468972 | Security: Two DoS bugs from OpenSSL 1.0.2a security advisory. | - | 2016-10-02 |
| 468936 | Pwn2own gpu bug | - | 2016-10-02 |
| 468931 | Security: Webpages have access to some extension resources | $3,000 | 2016-10-02 |
| 468933 | Security: pwn2own 2015 exploit #1 | - | 2016-10-02 |
| 468618 | ASSERTION FAILED: !value || (value->isValueList()) | - | 2016-10-02 |
| 468451 | Some cross-origin `location` properties are accessible | $3,000 | 2016-10-02 |
| 468179 | Alert popup with no and/or inaccurate origin identification | $500 | 2016-10-02 |
| 468167 | Use-of-uninitialized-value in parse_font_matrix | $1,000 | 2016-10-02 |
| 468519 | Container-overflow in blink::FEColorMatrix::createImageFilter | $1,500 | 2016-10-02 |
| 468406 | Container-overflow in blink::HTMLTreeBuilder::processStartTagForInBody | - | 2016-10-02 |
| 467644 | Bad-cast to blink::LayoutBox from blink::LayoutText;LayoutBox.h:NUMBER:1 | - | 2016-10-02 |
| 467452 | Heap-use-after-free in blink::Node::recalcDistribution | $2,000 | 2016-10-02 |
| 467481 | UNKNOWN in v8::base::NoBarrier_Load | - | 2016-10-02 |
| 467844 | Hosted apps running in windows don't show the origin. | - | 2016-10-02 |
| 468166 | Use-of-uninitialized-value in blink::Member<blink::IDBKey>* blink::HeapAllocator::allocateVectorBacking<b | $1,500 | 2016-10-02 |
| 467593 | UNKNOWN in SkBlitMask::RowFactory | - | 2016-10-02 |
| 467352 | UNKNOWN in gleUnbindDeleteHashNamesAndObjects | - | 2016-10-02 |
| 467347 | UNKNOWN in SkBlitLCD16OpaqueRow_SSE2 | - | 2016-10-02 |
| 467184 | Use-of-uninitialized-value in cc::LayerQuad::ToQuadF | - | 2016-10-02 |
| 467014 | Heap-use-after-free in blink::LayoutObject::container | - | 2016-10-02 |
| 467372 | Heap-use-after-free in base::MessageLoop::DeleteSoonInternal | - | 2016-10-02 |
| 467348 | Heap-use-after-free in blink::TextFieldInputType::handleKeydownEventForSpinButton | $1,500 | 2016-10-02 |
| 466990 | Heap-use-after-free in hb_ot_map_t::lookup_map_t::cmp | - | 2016-10-02 |
| 466967 | UNKNOWN in sk_memset32_SSE2 | $1,000 | 2016-10-02 |
| 466790 | Global-buffer-overflow in CPDF_CIDFont::_CharCodeFromUnicode | - | 2016-10-02 |
| 466338 | Security: Unchecked memcpy in _png_load_bmp_attribute() | - | 2016-10-02 |
| 466632 | Heap-use-after-free in v8::internal::Code::Disassemble | - | 2016-10-02 |
| 466351 | Security: On Android, it's possible to inject text and icons to the page info bubble using crafted URL fragments | $500 | 2016-10-02 |
| 467011 | Heap-buffer-overflow in SkAAClipBlitter::blitMask | - | 2016-10-02 |
| 465557 | Security: Browser-process out-of-bounds write of up to 7 bytes in BoringSSL ssl3_read_n. | - | 2016-10-02 |
| 465586 | Use-after-free in _XReply | - | 2016-10-02 |
| 466335 | Heap-use-after-free in content::WebSocketHost::AddChannel | - | 2016-10-02 |
| 465759 | Use-of-uninitialized-value in v8::internal::Factory::NewNumber | - | 2016-10-02 |
| 465517 | Origin header preserved for cross-origin redirects with 307 status code, should be null | - | 2016-10-02 |
| 465002 | UNKNOWN in PluginObserver::PluginPlaceholderHost::DownloadFinished | - | 2016-10-02 |
| 464995 | Heap-use-after-free in webrtc::DtlsIdentityStore::GenerateIdentity_w | - | 2016-10-02 |
| 464871 | Flash: use-after-free in display list handling from KeenTeam (repros 2-5, 6) | $4,000 | 2016-10-02 |
| 464870 | Flash: use-after-free in display list handling from KeenTeam (repro 1) | $3,000 | 2016-10-02 |
| 464792 | Heap-use-after-free in blink::FrameView::setScrollbarModes | - | 2016-10-02 |
| 465426 | Heap-use-after-free in get_lowest_part_y | - | 2016-10-02 |
| 465185 | Heap-use-after-free in std::_Tree<std::_Tset_traits<enum | - | 2016-10-02 |
| 465091 | Heap-buffer-overflow in blink::Document::Document | - | 2016-10-02 |
| 474609 | Heap-use-after-free in blink::HTMLImportTreeRoot::recalcTimerFired | - | 2016-10-02 |
| 474784 | Heap-use-after-free in blink::ScriptStreamer::streamingCompleteOnBackgroundThread | - | 2016-10-02 |
| 474783 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 474370 | Security: heap-use-after-free in content::MediaStreamDispatcher::OnStreamGenerated | $1,000 | 2016-10-02 |
| 474254 | Merge change to reject DHE for False Start | - | 2016-10-02 |
| 474099 | Security: Use-after-free in webaudio/scriptprocessornode-premature-death.html and webaudio/scriptprocessornode-premature-death.html | - | 2016-10-02 |
| 474297 | UNKNOWN in v8::internal::PropertyCell::UpdateCell | - | 2016-10-02 |
| 473688 | Heap-buffer-overflow in media::MultiChannelResampler::Resample | - | 2016-10-02 |
| 473253 | Security: heap-use-after-free in blink::ConsumerWrapper::consumeAudio | $3,000 | 2016-10-02 |
| 474082 | Container-overflow in TabDragController::GetTabsMatchingDraggedContents | - | 2016-10-02 |
| 474077 | UNKNOWN in v8::internal::NativeRegExpMacroAssembler::Execute | - | 2016-10-02 |
| 473903 | Clicking 'prevent additional dialogs' fails to work with some scammer sites | - | 2016-10-02 |
| 472613 | Heap-buffer-overflow in blink::UTF16TextIterator::consumeSlowCase | $500 | 2016-10-02 |
| 472201 | Security: Flash: Uninitialized stack variable while parsing an MPD file can corrupt memory | $3,000 | 2016-10-02 |
| 472147 | Heap-buffer-overflow in SuperBlitter::blitH | - | 2016-10-02 |
| 472146 | Heap-use-after-free in printing::PrintJobWorker::GetSettingsWithUIDone | - | 2016-10-02 |
| 471991 | Global-buffer-overflow in CXFA_ItemLayoutProcessor::CalculatePositionedContainerPos | - | 2016-10-02 |
| 471990 | UNKNOWN in CPDF_SampledFunc::v_Call | - | 2016-10-02 |
| 472614 | Heap-use-after-free in content::IndexedDBBackingStore::Transaction::ChainedBlobWriterImpl::ReportW | $3,500 | 2016-10-02 |
| 472618 | WebSQL shoudn't run a nested message loop during renderer shutdown. | - | 2016-10-02 |
| 472617 | Heap-use-after-free in content::UserMediaClientImpl::OnCreateNativeTracksCompleted | - | 2016-10-02 |
| 471651 | Heap-buffer-overflow in CPDF_CMap::GetNextChar | $500 | 2016-10-02 |
| 471525 | Heap-buffer-overflow in url::ParsePort | $1,000 | 2016-10-02 |
| 471523 | Security: Heap-use-after-free in extensions::`anonymous namespace'::LoadWatcher::DidCreateDocumentElement+68 | $3,000 | 2016-10-02 |
| 471445 | Bad-cast to blink::LayoutMultiColumnFlowThread from blink::LayoutTable;LayoutBlockFlow.cpp:3089:13 | - | 2016-10-02 |
| 471785 | Bad-cast to blink::DedicatedWorkerGlobalScope from blink::CompositorWorkerGlobalScope;WorkerMessagingProxy.cpp:76:47 | - | 2016-10-02 |
| 471652 | NO STACK | - | 2016-10-02 |
| 470980 | Security: Unknown in convolve4RowsHorizontally_SSE2 | - | 2016-10-02 |
| 471000 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 470837 | Security: Flash Player Integer Overflow in Function.apply | $7,500 | 2016-10-02 |
| 470777 | Heap-buffer-overflow in blink::WebSpeechRecognitionHandle::operator blink::SpeechRecognition* | - | 2016-10-02 |
| 471072 | UNKNOWN in S32A_Opaque_BlitRow32_SSE4 | - | 2016-10-02 |
| 470864 | Security: Use After Free in Flash AVSS.setSubscribedTags can cause memory corruption | $5,000 | 2016-10-02 |
| 470856 | Use-of-uninitialized-value in webrtc::internal::TransportAdapter::SendRTCPPacket | - | 2016-10-02 |
| 470470 | Heap-use-after-free in blink::PopupMenuImpl::addElementStyle | - | 2016-10-02 |
| 470391 | Use-of-uninitialized-value in v8::internal::Simulator::LoadStoreHelper | - | 2016-10-02 |
| 470390 | UNKNOWN in v8::internal::Heap::UpdateAllocationSiteFeedback | - | 2016-10-02 |
| 470749 | Flash: bad cast(?) in display list handling from KeenTean | $2,000 | 2016-10-02 |
| 470392 | UNKNOWN in v8::internal::FixedArray::get | - | 2016-10-02 |
| 470753 | Flash: out-of-bounds write in shader handling | $3,000 | 2016-10-02 |
| 470751 | Flash: AGAL information leak from KeenTeam | $1,000 | 2016-10-02 |
| 470121 | Bad-cast to webrtc::newapi::Transport from invalid vptr;transport_adapter.cc:36:18 | - | 2016-10-02 |
| 469814 | Looks like OOB call in memcpy | - | 2016-10-02 |
| 470144 | Heap-use-after-free in ImageDecoder::OnMessageReceived | - | 2016-10-02 |
| 469743 | UNKNOWN in libc.so.6 | - | 2016-10-02 |
| 469507 | Security: Screen contents from other origins and non-Chrome applications are displayed in the browser | $1,000 | 2016-10-02 |
| 469480 | NO STACK | $3,500 | 2016-10-02 |
| 470128 | UNKNOWN in v8::internal::TypeFeedbackOracle::CanRetainOtherContext | - | 2016-10-02 |
| 470122 | Heap-use-after-free in webrtc::internal::TransportAdapter::SendRTCPPacket | - | 2016-10-02 |
| 469756 | Use-of-uninitialized-value in blink::TransformationMatrix::rotate3d | - | 2016-10-02 |
| 469416 | Container-overflow in content::MidiMessageFilter::HandleClientAdded | - | 2016-10-02 |
| 481874 | Vulnerability reported in net-dialup/ppp | - | 2016-10-02 |
| 481299 | OS X memory corruption in IOAccelSurface2::set_shape_backing_length_ext from KEEN Team | $5,000 | 2016-10-02 |
| 481298 | OS X memory corruption in IGFence::release from KEEN Team | $5,000 | 2016-10-02 |
| 481296 | Apple OS X Yosemite 10.10.2 IOAccelSurface2::set_id_mode OOB read on IOAccelMachine2 from KEEN Team | $5,000 | 2016-10-02 |
| 481218 | OS X kASLR defeat from KEEN Team | $4,000 | 2016-10-02 |
| 481044 | Security: use-after-free in WebAudio | - | 2016-10-02 |
| 481015 | Security: XSS in the bookmark button | $500 | 2016-10-02 |
| 481639 | Security: Boundless Tunes - universal SOP bypass through ActionSctipt's Sound object | $7,500 | 2016-10-02 |
| 481306 | Flash use-after-free in display list handling from KEEN Team, round #2 | $3,000 | 2016-10-02 |
| 480536 | Container-overflow in /mnt/scratch0/clusterfuzz/slave-bot/builds/chromium-browser-asan_linux-rele | - | 2016-10-02 |
| 479825 | Use-after-free in blink::LayoutMenuList::setIndexToSelectOnCancel | - | 2016-10-02 |
| 479427 | ASSERTION FAILED: !object || (object->isLayoutBlock()) | - | 2016-10-02 |
| 479743 | Security: 1503A - Chrome - ui::AXTree::Unserialize UAF | - | 2016-10-02 |
| 480201 | Security: chrome url spoofing | $1,000 | 2016-10-02 |
| 478745 | Heap-use-after-free in blink::ContainerNode::addChildNodesToDeletionQueue | - | 2016-10-02 |
| 478575 | Heap-use-after-free in blink::Node::parentOrShadowHostOrTemplateHostNode | - | 2016-10-02 |
| 478578 | Heap-use-after-free in cc::ScrollbarLayerImplBase::PushScrollClipPropertiesTo | - | 2016-10-02 |
| 479162 | Security: spell checking dictionaries are fetched over HTTP, and large responses lead to a crash | $500 | 2016-10-02 |
| 478556 | UNKNOWN in v8::internal::ExecutableAccessorInfo::set_setter | - | 2016-10-02 |
| 478549 | Heap-use-after-free in blink::SMILTimeContainer::updateAnimations | $2,000 | 2016-10-02 |
| 478583 | Use-of-uninitialized-value in content::MediaInternals::OnMediaEvents | - | 2016-10-02 |
| 478009 | UNKNOWN in v8::internal::PropertyCell::PropertyCellVerify | - | 2016-10-02 |
| 478077 | Heap-use-after-free in v8::internal::CompilationDependencies::Abort | - | 2016-10-02 |
| 477953 | UNKNOWN in v8::internal::JSObject::JSObjectVerify | - | 2016-10-02 |
| 477868 | Decide on security style for resources loaded over bad HTTPS with user exception | - | 2016-10-02 |
| 477955 | UNKNOWN in v8::internal::FixedArray::FixedArrayVerify | - | 2016-10-02 |
| 477331 | Negative-size-param in cc::ListContainer<cc::DrawQuad>::EraseAndInvalidateAllPointers | - | 2016-10-02 |
| 477333 | ASSERTION FAILED: node.isElementNode() | - | 2016-10-02 |
| 477380 | Bad-cast to blink::RawResourceClient from blink::LinkLoader;RawResource.cpp:59:33 | - | 2016-10-02 |
| 477680 | Security: avatars are fetched over HTTP, and large responses lead to a crash | - | 2016-10-02 |
| 477713 | ASSERTION FAILED: !needsLayout | - | 2016-10-02 |
| 477819 | Heap-use-after-free in blink::FFTFrame::doInverseFFT | - | 2016-10-02 |
| 477298 | UNKNOWN in v8::internal::HeapObject::SizeFromMap | - | 2016-10-02 |
| 477278 | Security: URL spoof message of onbeforeunload | - | 2016-10-02 |
| 476926 | Security: Flash AS2 Use After Free in TextField.filters (again) | $5,000 | 2016-10-02 |
| 477089 | Heap-use-after-free in void blink::ScriptPromiseResolver::resolveOrReject<blink::AudioBuffer*> | - | 2016-10-02 |
| 476647 | Use-of-uninitialized-value in SkRecords::FillBounds::adjustAndMap | $500 | 2016-10-02 |
| 476107 | Heap-buffer-overflow in CJBig2_Context::parseSymbolDict | - | 2016-10-02 |
| 477187 | Heap-use-after-free in blink::AudioScheduledSourceHandler::notifyEnded | - | 2016-10-02 |
| 475749 | Heap-buffer-overflow in media::ChannelMixingMatrix::CreateTransformationMatrix | - | 2016-10-02 |
| 475773 | Heap-use-after-free in blink::LayoutBox::contentBoxRect | - | 2016-10-02 |
| 475070 | Security: Clank injects JavaScript into the main page's world | - | 2016-10-02 |
| 475018 | Security: [FLASH] Issues in DefineBitsLossless and DefineBitsLossless2 leads to using uninitialized memory while rendering a picture | $4,000 | 2016-10-02 |
| 489764 | boringssl: x509v3 has possible use-after-free in do_check_string() | - | 2016-10-02 |
| 488783 | Heap-buffer-overflow in url::CanonicalizeIPAddress | - | 2016-10-02 |
| 489151 | UNKNOWN in v8::internal::Simulator::LoadStoreHelper | - | 2016-10-02 |
| 487284 | Security: QCMS crash OOB read at src/chain.c:211 | - | 2016-10-02 |
| 487752 | Unsecure shared memory | - | 2016-10-02 |
| 487286 | Negative-size-param in content::AppCacheUpdateJob::OnDestructionImminent | - | 2016-10-02 |
| 487928 | Heap-use-after-free in CJS_WideStringArray::~CJS_WideStringArray | $4,337 | 2016-10-02 |
| 486947 | UNKNOWN in SkReader32::readString | $5,000 | 2016-10-02 |
| 486946 | UNKNOWN in _fini | $5,000 | 2016-10-02 |
| 487237 | Security: Flash AS2 Use After Free in DisplacementMapFilter.mapBitmap | $5,000 | 2016-10-02 |
| 486944 | Stack-buffer-overflow in SkPackBits::Unpack8 | $5,000 | 2016-10-02 |
| 486538 | Heap-double-free in opj_j2k_tcp_destroy | - | 2016-10-02 |
| 487155 | Security: CSP does not block svg image in nested iframe | $1,000 | 2016-10-02 |
| 486977 | Heap-buffer-overflow in SkData::NewUninitialized | $5,000 | 2016-10-02 |
| 486945 | Heap-double-free in SkPictureData::~SkPictureData | $5,000 | 2016-10-02 |
| 486434 | Stack-buffer-overflow in sandbox::BrokerServicesBase::SpawnTarget | $2,500 | 2016-10-02 |
| 486003 | UNKNOWN in v8::internal::Heap::EnsureDoubleAligned | - | 2016-10-02 |
| 486000 | Heap-use-after-free in blink::LayoutMultiColumnSet::updateMinimumColumnHeight | - | 2016-10-02 |
| 485893 | Security: Adobe Flash FLV SCRIPTDATDSTRING OOB read Information Leak | - | 2016-10-02 |
| 486301 | Heap-use-after-free in blink::BMPImageReader::decodeBMP | - | 2016-10-02 |
| 486004 | Heap-use-after-free in base::MessageLoop::PostTask | - | 2016-10-02 |
| 485843 | Use-after-poison in blink::PlatformSpeechSynthesizer::setVoiceList | - | 2016-10-02 |
| 485419 | UNKNOWN in v8::internal::Simulator::DecodeTypeImmediate | - | 2016-10-02 |
| 485414 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
| 485413 | Heap-use-after-free in ExtensionLocalizationPeer::OnCompletedRequest | - | 2016-10-02 |
| 485534 | Heap-use-after-free in v8::internal::JSObject::PrintElements | - | 2016-10-02 |
| 485198 | XSS Auditor bypass: <link rel="import {garbage}" | - | 2016-10-02 |
| 484998 | An integer overflow in libskia could be used to escalate from Chrome's sandbox in Android | $3,000 | 2016-10-02 |
| 484957 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 485855 | Heap-use-after-free in /mnt/scratch0/clusterfuzz/slave-bot/builds/chromium-browser-asan_linux-release/r | - | 2016-10-02 |
| 485412 | Heap-buffer-overflow in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
| 484610 | Security: Flash UAF with Color.setRGB in AS2 | $7,500 | 2016-10-02 |
| 484432 | Potential heap overflow in WebRTC's VCMEncodedFrame | - | 2016-10-02 |
| 484270 | Security: Heap overflow in CertificateResourceHandler | - | 2016-10-02 |
| 484211 | Apply upstream EAP-PWD, WPS and WMM fixes | - | 2016-10-02 |
| 484614 | Heap-use-after-free in blink::CSSAnimations::maybeApplyPendingUpdate | $3,000 | 2016-10-02 |
| 483981 | Security: Heap Overflow Vulnerability in JBIG2 handling, used by PDF Reader | $5,500 | 2016-10-02 |
| 483923 | Use-of-uninitialized-value in SkRect::join | - | 2016-10-02 |
| 483728 | UNKNOWN in v8::internal::RelocIterator::RelocIterator | - | 2016-10-02 |
| 483727 | Heap-use-after-free in blink::InspectorResolver::resolveFrame | - | 2016-10-02 |
| 483488 | Security: Service Workers let you bypass some same-origin checks (like verbose script parsing errors) | - | 2016-10-02 |
| 483375 | Security: [FG-VD-15-037] Adobe Flash Player PCRE Handing Heap Overflow Vulnerability | $3,000 | 2016-10-02 |
| 483340 | Heap-buffer-overflow in blink::RejectedPromises::processQueue | - | 2016-10-02 |
| 482639 | UNKNOWN in CJBig2_HuffmanTable::parseFromCodedBuffer | - | 2016-10-02 |
| 482521 | Security: Flash UAF with MovieClip.scrollRect in AS2 | $7,500 | 2016-10-02 |
| 483856 | Use-after-poison in blink::PendingScript::PendingScript | - | 2016-10-02 |
| 482369 | ASSERTION FAILED: !entry->element || entry->element == element | - | 2016-10-02 |
| 482380 | Security: URL Spoof with http authentication dialog and pdf prompt dialog | $500 | 2016-10-02 |
| 482214 | ASSERTION FAILED: !object || (object->isBox()) | $2,500 | 2016-10-02 |
| 498982 | Security: XSS Auditor info disclosure using iframe length from different domains | $1,337 | 2016-10-02 |
| 498954 | Heap-use-after-free in content::BrowserPlugin::~BrowserPlugin | - | 2016-10-02 |
| 498478 | Proximity Auth Base64URL decoding allows invalid messages through | - | 2016-10-02 |
| 498475 | Heap-use-after-free in blink::InspectorDebuggerAgent::removeBreakpoint | - | 2016-10-02 |
| 498338 | Security: Integer Overflow in Windows Sandbox Policy Engine String Comparison | - | 2016-10-02 |
| 497632 | Security: SEGV on unknown address in offsetHeightAttributeGetter | $3,000 | 2016-10-02 |
| 497588 | Security: Chrome Address Spoofing with unresponsive page | - | 2016-10-02 |
| 497579 | ASSERTION FAILED: offset + length <= m_length | - | 2016-10-02 |
| 498984 | Security: Flash AS2 Use After Free in TextField.filters (again and again) | $5,000 | 2016-10-02 |
| 497576 | UNKNOWN in v8::internal::ArrayConcatVisitor::ToArray | - | 2016-10-02 |
| 497523 | ASSERTION FAILED: !value || (value->isGridLineNamesValue()) | - | 2016-10-02 |
| 497578 | Heap-buffer-overflow in gfx::internal::TextRunHarfBuzz::GetClusterAt | - | 2016-10-02 |
| 497507 | Security: Cross-origin scripting possible via native functions | $7,500 | 2016-10-02 |
| 497435 | Heap-use-after-free in blink::LayoutMultiColumnSet::pageLogicalHeight | - | 2016-10-02 |
| 497357 | Heap-buffer-overflow in color_sycc_to_rgb | $1,000 | 2016-10-02 |
| 497355 | Heap-double-free in j2k_read_ppm_v3 | $3,000 | 2016-10-02 |
| 497195 | ASSERTION FAILED: !object || (object->isLayoutMultiColumnSet()) | - | 2016-10-02 |
| 497524 | Use-after-free in WTF::Vector<blink::MultiColumnFragmentainerGroup,1,WTF::DefaultAllocator>::at | - | 2016-10-02 |
| 495933 | Security: RTL character + IP address = spoofed domain | - | 2016-10-02 |
| 495682 | Use-of-uninitialized-value in /mnt/scratch0/clusterfuzz/slave-bot/builds/linux_msan_chrome_ipc/custom/msan_ipc | - | 2016-10-02 |
| 495300 | Security: heap-use-after-free in pdfium CFX_BaseSegmentedArray | - | 2016-10-02 |
| 494987 | Security: Geolocation API Spoof in Chrome For iOS | $500 | 2016-10-02 |
| 494640 | Security: Universal XSS using IDBKeyRange static methods | $7,500 | 2016-10-02 |
| 494043 | ASSERTION FAILED: !node || (node->isContainerNode()) | - | 2016-10-02 |
| 495934 | Security: Unicode "Lock" character ( | - | 2016-10-02 |
| 492981 | Heap-use-after-free in blink::HTMLFormElement::item | - | 2016-10-02 |
| 493243 | Heap-use-after-free in blink::Frame::deprecatedLocalOwner | $2,000 | 2016-10-02 |
| 493935 | Distinguish file: origins by hostname AND pathname, just not pathname | - | 2016-10-02 |
| 492448 | Security: Update NSS to 3.19 | - | 2016-10-02 |
| 492490 | ASSERTION FAILED: offset + length <= m_length | - | 2016-10-02 |
| 492634 | Security: Information for reporting Canary build bugs sends you to an insecure webpage | - | 2016-10-02 |
| 492263 | UNKNOWN in SkSweepGradient::SweepGradientContext::shadeSpan | $5,000 | 2016-10-02 |
| 492052 | Security: libexpat buffer-overflow seems to affect latest version of chromium on Linux x86_64 | $500 | 2016-10-02 |
| 491975 | Heap-buffer-overflow in SI8_opaque_D32_nofilter_DX | $1,000 | 2016-10-02 |
| 491742 | UNKNOWN in v8::internal::Simulator::DecodeType2 | - | 2016-10-02 |
| 492265 | Heap-use-after-free in SkCreateBitmapShader | $1,000 | 2016-10-02 |
| 491660 | Heap-buffer-overflow in convolve4RowsHorizontally_SSE2 | $5,000 | 2016-10-02 |
| 491584 | Use-of-uninitialized-value in media::VideoFrameCompositor::GetCurrentFrameAndUpdateIfStale | - | 2016-10-02 |
| 491582 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
| 491216 | Make IOBuffer, IOBufferWithSize and ShrinkableIOBufferWithSize resilient against truncation. | - | 2016-10-02 |
| 490721 | Heap-buffer-overflow in blink::CSSSelector::matchNth | - | 2016-10-02 |
| 490722 | Heap-use-after-free in blink::LayoutMultiColumnSet::flowThreadTranslationAtOffset | - | 2016-10-02 |
| 490506 | UNKNOWN in v8::internal::CompilationDependencies::Abort | - | 2016-10-02 |
| 490505 | Heap-use-after-free in blink::AXObject::document | - | 2016-10-02 |
| 490496 | Heap-use-after-free in plugins::LoadablePluginPlaceholder::DidFinishLoadingCallback | - | 2016-10-02 |
| 490492 | Security: heap-use-after-free in WebsiteSettingsInfoBarDelegate::Create | $1,000 | 2016-10-02 |
| 505614 | Use-of-uninitialized-value in std::__1::__tree<content::WebContents*, std::__1::less<content::WebContents*>, s | - | 2016-10-02 |
| 505374 | UNKNOWN in blink::EventTarget::getEventListeners | $1,000 | 2016-10-02 |
| 505341 | UNKNOWN in v8::internal::ScopeIterator::Type | - | 2016-10-02 |
| 505227 | Use-of-uninitialized-value in GrAAConvexTessellator::addTri | - | 2016-10-02 |
| 504691 | Heap-buffer-overflow in content::NavigationControllerImpl::RendererDidNavigateToExistingPage | - | 2016-10-02 |
| 504688 | Heap-use-after-free READ 8 in blink::DeprecatedPaintLayer::mapRectToPaintBackingCoordinates | - | 2016-10-02 |
| 504727 | UNKNOWN in v8::internal::Object::GetProperty | - | 2016-10-02 |
| 504692 | Heap-use-after-free in views::internal::NativeWidgetPrivate::GetNativeWidgetForNativeView | - | 2016-10-02 |
| 504687 | Use-of-uninitialized-value in SkCanvas::concat | - | 2016-10-02 |
| 504690 | Use-of-uninitialized-value in blink::encodePixels | - | 2016-10-02 |
| 504685 | Heap-use-after-free in blink::WorkerScriptLoader::loadAsynchronously | - | 2016-10-02 |
| 503217 | Security: improperly escaped "saved from url" info allows modification of saved pages | $500 | 2016-10-02 |
| 502863 | Use-after-poison in blink::HTMLMediaElement::setReadyState | - | 2016-10-02 |
| 502859 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
| 502794 | Heap-use-after-free in CFX_BaseSegmentedArray::Iterate | - | 2016-10-02 |
| 502793 | Heap-use-after-free in blink::Touch::Touch | - | 2016-10-02 |
| 502792 | Stack-buffer-overflow in FixWinding | - | 2016-10-02 |
| 502858 | Heap-use-after-free in blink::SuspendableScriptExecutor::contextDestroyed | - | 2016-10-02 |
| 501973 | Heap-double-free in gfxReleaseSharedStateAndHash | - | 2016-10-02 |
| 501891 | Bad-cast to blink::EventTarget from blink::MediaDevices;ScriptWrappable.h:67:16 | - | 2016-10-02 |
| 501888 | Heap-use-after-free in blink::ScreenOrientationController::dispatchChangeEvent | - | 2016-10-02 |
| 502562 | Heap-use-after-free in WebLocalFrameImpl::printBegin | $3,000 | 2016-10-02 |
| 501889 | Heap-buffer-overflow in CPDF_ICCBasedCS::GetDefaultValue | - | 2016-10-02 |
| 500877 | Security: XSSAuditor bypass with leading regexp inside svg script tag. | - | 2016-10-02 |
| 501428 | Stack-use-after-return in blink::DisplayItemClientWrapper::displayItemClient | - | 2016-10-02 |
| 501113 | Vulnerability reported in dev-libs/openssl | - | 2016-10-02 |
| 500026 | Security: Non-temporal store row-hammer vulnerability | - | 2016-10-02 |
| 499789 | Heap-use-after-free in v8::internal::JSTypedArray::MaterializeArrayBuffer | - | 2016-10-02 |
| 500355 | Heap-use-after-free in v8::HandleScope::Initialize | - | 2016-10-02 |
| 500175 | Heap-buffer-overflow in v8::internal::JSTypedArray::MaterializeArrayBuffer | - | 2016-10-02 |
| 500352 | Use-after-poison in blink::HTMLMediaElement::~HTMLMediaElement | - | 2016-10-02 |
| 499279 | Web MIDI performance crashes chrome canary | $2,000 | 2016-10-02 |
| 499465 | Security: WebKit ASLR is consistent across renderers | - | 2016-10-02 |
| 512445 | Heap-use-after-free in in CPDFSDK_PageView::GetAnnotByDict | - | 2016-10-02 |
| 511554 | Vulnerability reported in net-misc/curl-7.23.1-r1 | - | 2016-10-02 |
| 511616 | Security: Performance APIs reveal cross-origin URLs. | $1,000 | 2016-10-02 |
| 511553 | Vulnerability reported in dev-libs/openssl-1.0.1c-r9 | - | 2016-10-02 |
| 509775 | Remove unused jump_elimination_allowed parameter to Assembler::branch_offset() | - | 2016-10-02 |
| 510702 | Heap-use-after-free in blink::CompositorWorkerManager::shutdown | - | 2016-10-02 |
| 510707 | Heap-use-after-free in blink::Font::buildTextBlob | - | 2016-10-02 |
| 510802 | Security: webRequest API allows intercepting XHR from apps and extensions | $3,000 | 2016-10-02 |
| 510850 | Security: Chrome inadvertently includes a supercookie via DTLS cert information | - | 2016-10-02 |
| 509666 | Security: ARM constant pool can be blocked for too long | - | 2016-10-02 |
| 509463 | ASSERTION FAILED: !object || (object->isLayoutMultiColumnSet()) | - | 2016-10-02 |
| 509461 | Heap-use-after-free in blink::Node::insertBefore | - | 2016-10-02 |
| 509458 | Heap-use-after-free in v8::internal::MemoryReducer::TimerTask::Run | $3,500 | 2016-10-02 |
| 509670 | MIPS trampoline pool emission seems to be wrong sometimes | - | 2016-10-02 |
| 509313 | chrome.embeddedSearch.newTabPage.navigateContentWindow is too powerful | $1,000 | 2016-10-02 |
| 508792 | Uninit read from cc::LayerTreeHostImpl::LayerTreeHostImpl | - | 2016-10-02 |
| 508705 | Use-of-uninitialized-value in blink::MediaQueryExp::createIfValid | - | 2016-10-02 |
| 508703 | Use-of-uninitialized-value in AAFillRectBatch::onCombineIfPossible | - | 2016-10-02 |
| 508540 | Unicode-decoder: fix out-of-band write in utf16 | - | 2016-10-02 |
| 508086 | Security: Flash UAF with Color.setTransform in AS2 | - | 2016-10-02 |
| 508983 | ASSERTION FAILED: !node || (node->isShadowRoot()) | - | 2016-10-02 |
| 508979 | Heap-use-after-free in blink::DeprecatedPaintLayer::setGroupedMapping | - | 2016-10-02 |
| 508876 | GetStringUTFChars() no longer returns Modified UTF-8 in Android M | - | 2016-10-02 |
| 508872 | Merge out-of-bounds accesses found by WebRTC fuzzing. | - | 2016-10-02 |
| 507990 | Use-after-free in blink::V8Window::namedPropertyGetterCustom | - | 2016-10-02 |
| 507988 | Heap-use-after-free in blink::DeprecatedPaintLayer::setGroupedMapping | $3,500 | 2016-10-02 |
| 507821 | Send SafeBrowsing ping-backs for additional file types | - | 2016-10-02 |
| 508072 | Security: Flash Heap-use-after-free in SurfaceFilterList::CĂąÂÂreateFromScriptAtom. Alwayzzzzzzz | $7,500 | 2016-10-02 |
| 507020 | Use-after-free in blink::AXNodeObject::document | - | 2016-10-02 |
| 507018 | Use-of-uninitialized-value in Browser::GetSecurityStyle | - | 2016-10-02 |
| 508009 | Security: Flash Use After Free in TextLine.opaqueBackground | - | 2016-10-02 |
| 507992 | Heap-use-after-free in blink::DeprecatedPaintLayer::updatePagination | - | 2016-10-02 |
| 507272 | Potential Flash 0-day Exploit ('flash-0day-vitaly1') | - | 2016-10-02 |
| 506749 | Heap-use-after-free in crypto::Encryptor::Decrypt | - | 2016-10-02 |
| 507017 | Use-of-uninitialized-value in blink::GraphicsContext::realizePaintSave | - | 2016-10-02 |
| 506763 | stack-use-after-return in opj_pi_next_rpcl | $500 | 2016-10-02 |
| 506540 | UNKNOWN in v8::internal::Simulator::InstructionDecode | - | 2016-10-02 |
| 505829 | Byte Serving Information Leak | - | 2016-10-02 |
| 516365 | Heap-use-after-free in media::DecryptingDemuxerStream::~DecryptingDemuxerStream | - | 2016-10-02 |
| 516298 | Many media/track/ layout tests flakily crash | - | 2016-10-02 |
| 516266 | Stack-buffer-overflow in SkIntersections::removeOne | $3,000 | 2016-10-02 |
| 516361 | Heap-buffer-overflow in gfx::FindValidBoundaryBefore | - | 2016-10-02 |
| 516690 | Security: WebUI backends inject data into random web pages (tracking bug) | - | 2016-10-02 |
| 514758 | Use-of-uninitialized-value in SkUnPreMultiply::UnPreMultiplyPreservingByteOrder | - | 2016-10-02 |
| 514756 | Use-of-uninitialized-value in SuperBlitter::blitH | - | 2016-10-02 |
| 516088 | Heap-buffer-overflow in content::NavigationControllerImpl::InsertOrReplaceEntry | - | 2016-10-02 |
| 514891 | Heap-buffer-overflow in CJBig2_Context::parseSymbolDict | $2,000 | 2016-10-02 |
| 514759 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
| 514080 | !field_type->NowStable() || field_type->NowContains(value) in src/objects-debug. | - | 2016-10-02 |
| 514076 | Security: localStorage of file:// can be read from any remote origin through a blob: document with the origin of null | $1,000 | 2016-10-02 |
| 514122 | UNKNOWN in v8::internal::MemoryChunk::IsFlagSet | - | 2016-10-02 |
| 514755 | Heap-use-after-free in blink::ComposedTreeTraversal::traverseParent | - | 2016-10-02 |
| 514753 | Use-of-uninitialized-value in blink::Font::glyphDataForCharacter | - | 2016-10-02 |
| 513917 | Heap-use-after-free in ui::InputMethodAuraLinux::ResetContext | - | 2016-10-02 |
| 513602 | UNKNOWN in v8::internal::Invoke | - | 2016-10-02 |
| 512678 | Security: CSS font loading API bypasses CORS | $500 | 2016-10-02 |
| 526286 | Container-overflow in blink::HTMLTreeBuilder::processStartTagForInBody | - | 2016-10-02 |
| 526441 | Use-of-uninitialized-value in vp3_h_loop_filter_c | - | 2016-10-02 |
| 526378 | Security: Pointerlock browser UI hijack | - | 2016-10-02 |
| 526025 | SEGV in SkOpSpan::containsCoincidence | - | 2016-10-02 |
| 526244 | Attempting free in v8::internal::Heap::FreeDeadArrayBuffersHelper | - | 2016-10-02 |
| 525696 | ASSERTION FAILED: !containsWrapper() | - | 2016-10-02 |
| 525330 | Null out DOMWindow::m_frame as soon as the frame/window is detached | - | 2016-10-02 |
| 524899 | Adobe Flash Player AdBreakTimelineItem class Memory Corruption Vulnerability | $3,000 | 2016-10-02 |
| 525832 | chromewebdata intermediary page can throw a Javascript syntax error | - | 2016-10-02 |
| 525763 | Heap-buffer-overflow in SkCreateBitmapShader | - | 2016-10-02 |
| 524096 | Use-of-uninitialized-value from GpuCommandBufferStub::OnInitializeFailed() | - | 2016-10-02 |
| 524094 | Use-of-uninitialized-value in GrTextureDomain::GLDomain::setData | - | 2016-10-02 |
| 524694 | Heap-use-after-free in blink::FrameLoaderClientImpl::dispatchDidFinishDocumentLoad | - | 2016-10-02 |
| 524682 | Bad-cast to blink::LayoutText from blink::LayoutBlockFlow;LayoutText.h:237:1 | - | 2016-10-02 |
| 524074 | Security: Universal XSS by loading a javascript: URI from an unloaded window | $7,500 | 2016-10-02 |
| 522791 | Security: Universal XSS using navigator.serviceWorker.ready | $7,500 | 2016-10-02 |
| 523453 | UNKNOWN in v8::internal::Deserializer::FlushICacheForNewCodeObjects | - | 2016-10-02 |
| 522128 | Security: Blink passes NULL TypedArray backing stores to V8, leading to OOB R/W | - | 2016-10-02 |
| 521655 | window.find() with unusual HTML fails to handle shadow tree | - | 2016-10-02 |
| 522131 | UNKNOWN in _CMapLookupCallback | $3,000 | 2016-10-02 |
| 521588 | Security: leaking previous webpage through webGL canvas preserveDrawingbuffer and scissor. | - | 2016-10-02 |
| 519558 | Security: Universal XSS via ContainerNode::parserInsertBefore | $8,837 | 2016-10-02 |
| 520422 | Security: Cross-site read access to PDF files | $4,000 | 2016-10-02 |
| 520792 | Heap-use-after-free in blink::DocumentLoader::dataReceived | - | 2016-10-02 |
| 521343 | Popunder is possible again (seemingly using Flash) | - | 2016-10-02 |
| 519642 | Security: Memory-safety bug in Image11::map | $1,000 | 2016-10-02 |
| 518827 | Security: chrome.runtime.setUninstallURL does not validate its URL parameter | $3,000 | 2016-10-02 |
| 517906 | Security: Installed extensions can read memory mapping information. | - | 2016-10-02 |
| 517854 | Global-buffer-overflow in FXSYS_itoa | - | 2016-10-02 |
| 518749 | Security: Heap-use-after-free in UsbContext::UsbEventHandler::Stop | $3,000 | 2016-10-02 |
| 518206 | Security: Overflow in VertexBufferInterface::reserveVertexSpace causes memory-safety bug | $5,000 | 2016-10-02 |
| 517913 | ASSERTION FAILED: it != m_scriptsToExecuteInOrder.end() | - | 2016-10-02 |
| 516821 | latest Chrome Canary(syzyasan) crashes constantly when querying crbug.com | - | 2016-10-02 |
| 517383 | Adobe Flash Player Regular Expression Out-Of-Bounds Write Remote Code Execution Vulnerability | $3,000 | 2016-10-02 |
| 534621 | Update FreeType with a recent series of patches | - | 2016-10-02 |
| 534570 | CSP: wildcard source expression (*) should not match data URIs | $500 | 2016-10-02 |
| 534542 | CSP: `*.x.y` must match a host that ends with `.x.y` (4.2.2 step 4.6) | $500 | 2016-10-02 |
| 532967 | UNKNOWN in vp8_read_mv_component | $500 | 2016-10-02 |
| 533778 | Security: Changing URL from your website to any other that uses HTTP BASIC AUTHENTICATION. | - | 2016-10-02 |
| 533520 | Security: Links to "file://" URLs in PDFs | - | 2016-10-02 |
| 532758 | Vulnerability reported in libpng | - | 2016-10-02 |
| 532450 | Vulnerability reported in sys-kernel/chromeos-kernel-3_10 | - | 2016-10-02 |
| 532448 | Vulnerability reported in sys-kernel/chromeos-kernel-3_10 | - | 2016-10-02 |
| 532762 | Vulnerability reported in libevent | - | 2016-10-02 |
| 532449 | Vulnerability reported in sys-kernel/chromeos-kernel-3_10 | - | 2016-10-02 |
| 531891 | Security: Universal XSS using exceptions thrown from Object.observe | $7,500 | 2016-10-02 |
| 532439 | Vulnerability reported in sys-kernel/chromeos-kernel-3_8 | - | 2016-10-02 |
| 532440 | Vulnerability reported in sys-kernel/chromeos-kernel-3_8 | - | 2016-10-02 |
| 531057 | Bad-cast to blink::ScriptWrappable from blink::WorkerWebSocketChannel;DOMWrapperMap.h:148:20 | $3,500 | 2016-10-02 |
| 530301 | Security: Universal XSS using stack overflow exceptions | $7,500 | 2016-10-02 |
| 529682 | Content script is able to eval code in background page of other extension | $3,000 | 2016-10-02 |
| 531664 | CFI: invalid cast in list_container.h | - | 2016-10-02 |
| 529530 | Heap-use-after-free in blink::DateTimeChooserImpl::didClosePopup | - | 2016-10-02 |
| 529527 | Use-of-uninitialized-value in content::EchoInformation::UpdateAecDelayStats | - | 2016-10-02 |
| 529520 | Heap-use-after-free in content::EmbeddedWorkerInstance::ReleaseProcess | $3,500 | 2016-10-02 |
| 529489 | Security: Tracking bug for upstream NSS issues | - | 2016-10-02 |
| 529310 | Bad-cast to CJS_EventHandler from ;PublicMethods.cpp:2026:7 | - | 2016-10-02 |
| 529552 | Heap-buffer-overflow in UpdateDelayMetrics | - | 2016-10-02 |
| 529531 | Heap-use-after-free in blink::WebViewImpl::close | - | 2016-10-02 |
| 529012 | Bad-cast to util from Document;JS_Define.h:165:13 | $3,500 | 2016-10-02 |
| 528798 | Bad-cast to blink::ScriptWrappable from blink::WebGLRenderingContextBase::TypedExtensionTracker<blink::ANGLEInstancedArrays>;ScriptWrappable.h:192:32 | - | 2016-10-02 |
| 528505 | Security: Linking to chrome:// urls inside pdf | $4,000 | 2016-10-02 |
| 528799 | Bad-cast to icu_54::UnicodeSet from icu_54::Quantifier;rbt_pars.cpp:1105:22 | - | 2016-10-02 |
| 528628 | Heap-buffer-overflow in C:\clusterfuzz\slave-bot\builds\chrome-test-builds_media_win32-release_e999b7478 | - | 2016-10-02 |
| 527466 | Security: Linux x86_64 vsyscall provides attack vectors | - | 2016-10-02 |
| 527514 | Security: SAN-01-001 Angular ngSanitize bypass using SVG <use> & insecure JSON Callback in Blink | - | 2016-10-02 |
| 527423 | Security: Integer overflow in open-vcdiff results in OOB read in browser process | - | 2016-10-02 |
| 545173 | Security: UAF in CPWL_ComboBox::OnKeyDown in PDFium | - | 2016-10-02 |
| 544765 | Privacy: browser history sniffing attack using HSTS + CSP | $500 | 2016-10-02 |
| 544691 | Use-of-uninitialized-value in blink::encodePixels | $2,000 | 2016-10-02 |
| 544020 | Security: blink::WeekInputType uaf vulnerability | $3,000 | 2016-10-02 |
| 543994 | Crash in NULL@0x...60 | - | 2016-10-02 |
| 543528 | Heap-use-after-free in v8::internal::compiler::DeadCodeElimination::ReduceLoopOrMerge | - | 2016-10-02 |
| 544270 | Update harfbuzz to 1.0.6 | - | 2016-10-02 |
| 542054 | Security: properly escaped href attribute leading to offline XSS upon saving a page | $500 | 2016-10-02 |
| 541669 | Security: Security: signed integer overflow in media/formats/mp2t/es_parser_h264.cc | - | 2016-10-02 |
| 541594 | Bad-cast to v8::String::ExternalStringResource from invalid vptr;objects-inl.h:4047:10 | - | 2016-10-02 |
| 541593 | Heap-buffer-overflow in blink::SVGFilterGraphNodeMap::addPrimitive | $1,500 | 2016-10-02 |
| 542060 | CSP for Evil & Service Workers | - | 2016-10-02 |
| 541323 | Heap-buffer-overflow in CJBig2_HuffmanTable::parseFromCodedBuffer | - | 2016-10-02 |
| 541322 | Bad-cast to blink::WebTaskRunner from invalid vptr;BackgroundHTMLParser.cpp:109:36 | - | 2016-10-02 |
| 540949 | Security: Webpage can bypass arbitrary interstitial using HTTP auth dialog | - | 2016-10-02 |
| 539908 | Heap-use-after-free in blink::RejectedPromises::processQueueNow | - | 2016-10-02 |
| 539875 | Security: Symbols ignored in Object.{freeze, seal, isFrozen, isSealed}() | - | 2016-10-02 |
| 539691 | Heap-buffer-overflow in SkBlitter::blitMask | - | 2016-10-02 |
| 541415 | Security: URL Spoofing when victim tries to access another website from attacker's page. | $500 | 2016-10-02 |
| 541206 | Security: Universal XSS using document.adoptNode | $7,500 | 2016-10-02 |
| 539563 | Heap-buffer-overflow in net::HpackEncoder::EncodeHeaderSet | - | 2016-10-02 |
| 538952 | Bad-cast to Profile from invalid vptr;chrome_extensions_network_delegate.cc:38:22 | - | 2016-10-02 |
| 537666 | Remove references to unloadEvent in runtime_custom_bindings.js | - | 2016-10-02 |
| 538256 | Heap-use-after-free in blink::FrameLoaderClientImpl::dispatchDidFinishDocumentLoad | - | 2016-10-02 |
| 538257 | Crash in v8::internal::FlexibleBodyVisitor<v8::internal::MarkCompactMarkingVisitor,v8::in | - | 2016-10-02 |
| 537823 | Security: The password manager can be tricked to put one site's saved credential's into another's with HTTP auth | - | 2016-10-02 |
| 537205 | Security: Crazy Linker on Android allows modification of Chrome APK without breaking signature | $1,000 | 2016-10-02 |
| 536917 | Heap-use-after-free in blink::RadioInputType::didDispatchClick | - | 2016-10-02 |
| 537656 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
| 537173 | Security: PureCall on CPWL_Edit::OnKillFocus | $3,000 | 2016-10-02 |
| 537660 | Remove stash_client.js dependency on unload_event | - | 2016-10-02 |
| 537658 | Remove extension dependencies on unload_event.js | - | 2016-10-02 |
| 536601 | Crash in ff_sbr_hf_apply_noise_3_sse2 | - | 2016-10-02 |
| 536231 | Heap-double-free in v8::internal::ArrayBufferTracker::FreeDead | - | 2016-10-02 |
| 535605 | heap-use-after-free in AudioOutputDevice | - | 2016-10-02 |
| 536701 | Chrome mobile for iOS thinks JavaScript redirects are a form of certificate spoofing of trusted domains | $500 | 2016-10-02 |
| 536652 | Security: Disrupting the omnibox from the attacker's website. | $1,000 | 2016-10-02 |
| 536640 | Heap-use-after-free in blink::InlineTextBox::selectionState | - | 2016-10-02 |
| 534994 | Heap-use-after-free in extensions::BookmarkAppHelper::OnBubbleCompleted | - | 2016-10-02 |
| 534923 | Security: Universal XSS via the unload_event module | $7,500 | 2016-10-02 |
| 534992 | Heap-use-after-free in blink::TimerBase::stop | - | 2016-10-02 |
| 534993 | Heap-use-after-free in blink::CSSImageSetValue::valueWithURLsMadeAbsolute | - | 2016-10-02 |
| 555784 | Heap-buffer-overflow in CCodec_RLScanlineDecoder::v_GetNextLine | - | 2016-10-02 |
| 555575 | Heap-use-after-free in webrtc::PeerConnection::OnSessionStateChange | - | 2016-10-02 |
| 555544 | crash in SkSweepGradient::SweepGradientContext::shadeSpan | $2,000 | 2016-10-02 |
| 554648 | Factory reset can be performed when it should be disallowed. | - | 2016-10-02 |
| 554172 | Heap-buffer-overflow in opj_jp2_apply_pclr | - | 2016-10-02 |
| 554151 | Heap-buffer-overflow in CPDF_DIBSource::DownSampleScanline32Bit | - | 2016-10-02 |
| 554129 | Heap-buffer-overflow in opj_j2k_read_mcc | - | 2016-10-02 |
| 554115 | Heap-buffer-overflow in CPDF_TextObject::CalcPositionData | - | 2016-10-02 |
| 554946 | Security: Pwn2Own mobile case, out-of-bound access in json stringifier | $7,500 | 2016-10-02 |
| 554908 | Security: AppCacheDispatcherHost UaF with host transfer | $10,000 | 2016-10-02 |
| 554099 | Crash in v8::internal::StaticMarkingVisitor<v8::internal::IncrementalMarkingMarkingVisito | - | 2016-10-02 |
| 553050 | Heap-use-after-free in blink::PartPainter::isSelected | - | 2016-10-02 |
| 553054 | Heap-use-after-free in blink::V8SVGMatrix::visitDOMWrapper | - | 2016-10-02 |
| 552870 | ASSERTION FAILED: index < arraySize | - | 2016-10-02 |
| 553049 | Use-of-uninitialized-value in blink::LayoutObject::findNextLayer | - | 2016-10-02 |
| 552749 | window.crypto.getRandomValues() uses a weak CSPRNG | $500 | 2016-10-02 |
| 553048 | Heap-use-after-free in blink::LayoutBlock::removeChild | $3,500 | 2016-10-02 |
| 552448 | Security: PDFium: XFA: UAF in CXFA_PDFFontMgr::~CXFA_PDFFontMgr() | - | 2016-10-02 |
| 552046 | Heap-buffer-overflow in CPDF_DIBSource::GetScanline | - | 2016-10-02 |
| 551503 | Heap-buffer-overflow in cff_get_glyph_name | - | 2016-10-02 |
| 551470 | Heap-buffer-overflow in opj_t2_read_packet_header | - | 2016-10-02 |
| 551460 | Stack-buffer-overflow in CPDF_Function::Call | - | 2016-10-02 |
| 551116 | chrome crash during dark resume leaves zombie processes, reparented to init, which makes new chrome instance unusable. | - | 2016-10-02 |
| 551044 | Security: AppCacheUpdateJob accesses map::end() | $11,337 | 2016-10-02 |
| 551028 | FreeType : pick up post-2.6.1 patches (or 2.6.2 when it's out) | - | 2016-10-02 |
| 550972 | Security: app_mode_loader not signed on OSX | - | 2016-10-02 |
| 551288 | Crash in v8::internal::Heap::DoScavenge | - | 2016-10-02 |
| 550629 | Heap-use-after-free in content::RenderMessageFilter::OnKeygen | - | 2016-10-02 |
| 551143 | Heap-use-after-free in content::BindWebGraphicsContext3DGLContextCallback | - | 2016-10-02 |
| 550632 | Use-after-poison in blink::WorkerWebSocketChannel::Bridge::traceImpl<blink::InlinedGlobalMarkingVisi | $3,500 | 2016-10-02 |
| 549155 | Use-of-uninitialized-value in filter8 | - | 2016-10-02 |
| 550047 | Security: Inline extension installation dialog doesn't block and persists after redirect | $1,000 | 2016-10-02 |
| 546849 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
| 546848 | ASSERTION FAILED: !m_pendingInOrderScripts.isEmpty() | - | 2016-10-02 |
| 546846 | Heap-use-after-free in views::NativeWidgetAura::ShouldDescendIntoChildForEventHandling | - | 2016-10-02 |
| 546545 | Security: Universal XSS using plugin objects | $7,500 | 2016-10-02 |
| 545520 | Heap-buffer-overflow in blink::MarkupFormatter::appendCharactersReplacingEntities | - | 2016-10-02 |
| 567688 | Vulnerability reported in dev-libs/openssl | - | 2016-10-02 |
| 567445 | Security: URL Spoofing with HTTPS lock | $1,000 | 2016-10-02 |
| 566156 | Security: QUIC may send requests (including cookies) in the clear | - | 2016-10-02 |
| 566142 | Heap-use-after-free in blink::WebLocalFrameImpl::didFail | - | 2016-10-02 |
| 566231 | Security: chromeos-base/chromeos-ca-certificates is out of date | - | 2016-10-02 |
| 565760 | Security: Drop-downs hiding any part of the browser UI, allowing for several types of spoof attacks | $3,133 | 2016-10-02 |
| 565543 | Privileged installer directory is writeable by lower privileged users | - | 2016-10-02 |
| 565967 | Heap-use-after-free in webrtc::VCMGenericDecoder::Release | - | 2016-10-02 |
| 565416 | Security: OpenSSL 1.0.2e fixes | - | 2016-10-02 |
| 565048 | Heap-use-after-free in webrtc::DataChannel::UpdateState | - | 2016-10-02 |
| 565046 | Crash in v8::internal::RootMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
| 565023 | Security: Google Chrome: Privilege Escalation from Renderer Process to Browser Process | - | 2016-10-02 |
| 564501 | Security: UAF in MidiHost (Sandbox escape) | - | 2016-10-02 |
| 564238 | Security: Windows Image Sections Allow Mapping Arbitrary Executable Memory into More Privileged Processes | - | 2016-10-02 |
| 563964 | Security: GPU process to privileged renderer IPC bug? | - | 2016-10-02 |
| 565049 | Heap-use-after-free in blink::FrameSelection::notifyLayoutObjectOfSelectionChange | - | 2016-10-02 |
| 562986 | Heap-use-after-free in blink::FrameLoader::init | - | 2016-10-02 |
| 562984 | Use-of-uninitialized-value in blink::CachingWordShapeIterator::nextWord | - | 2016-10-02 |
| 561972 | Crash in v8::internal::HeapObject::VerifyHeapPointer | - | 2016-10-02 |
| 563688 | Security: Code Review Clickjacking | - | 2016-10-02 |
| 562208 | Heap-use-after-free in blink::LayoutBoxModelObject::hasSelfPaintingLayer | - | 2016-10-02 |
| 561497 | Heap-use-after-free in content::VideoCaptureController::RemoveClient | - | 2016-10-02 |
| 561505 | Global-buffer-overflow in blink::getPropertyName | - | 2016-10-02 |
| 561869 | Bad-cast to blink::StaticBitmapImage from blink::BitmapImage;ImageBitmap.cpp:51:25 | - | 2016-10-02 |
| 561488 | Heap-buffer-overflow in blink::appendCharactersReplacingEntitiesInternal<unsigned char const > | - | 2016-10-02 |
| 561478 | Heap-use-after-free in FT_Stream_ReleaseFrame | - | 2016-10-02 |
| 560480 | Global-buffer-overflow in blink::getPropertyName | - | 2016-10-02 |
| 560291 | Security: security vulnerabilities in libpng (CVE-2015-7981, CVE-2015-8126) | $500 | 2016-10-02 |
| 561492 | Heap-use-after-free in blink::PlatformEventDispatcher::notifyControllers | - | 2016-10-02 |
| 559528 | Heap-use-after-free in blink::LayoutTextFragment::setTextFragment | - | 2016-10-02 |
| 559515 | Security: Bypass to Multiple Files dialog allows for system crash or disk exhaustion | - | 2016-10-02 |
| 560011 | Security: Universal XSS using widget updates in ContainerNode::parserRemoveChild | $8,000 | 2016-10-02 |
| 559292 | Security: heap-use-after-free in blink::ScopedStyleResolver::collectMatchingAuthorRules | $3,000 | 2016-10-02 |
| 559075 | Vulnerability reported in net-misc/strongswan | - | 2016-10-02 |
| 559541 | Flash: Uninitialized variable in DateObject::_toString can cause memory corruption | $5,000 | 2016-10-02 |
| 559310 | Security: SharedWorkerDevToolsAgentHost UAF (sandbox escape) | - | 2016-10-02 |
| 558589 | Security: AppCacheUpdateJob UaF | $10,000 | 2016-10-02 |
| 557981 | Security: heap-use-after-free in blink::MutationObserver::enqueueMutationRecord | $2,000 | 2016-10-02 |
| 557806 | Heap-use-after-free: text-transform CSS property breaks document life time cycle | - | 2016-10-02 |
| 557802 | Bad-cast to blink::HTMLOptionElement from blink::HTMLOptGroupElement;Element.h:704:12 | - | 2016-10-02 |
| 558840 | Crash in NULL@0x...40 | - | 2016-10-02 |
| 557799 | Crash in Init | - | 2016-10-02 |
| 557797 | Heap-use-after-free in I422ToARGBRow_Any_SSSE3 | - | 2016-10-02 |
| 557223 | Pdfium heap-buffer-overflow in sycc422_to_rgb | $500 | 2016-10-02 |
| 556725 | Investigate legality of call to ContextGL in RenderThreadImpl::SharedWorkerContextProvider | - | 2016-10-02 |
| 556724 | Security: Universal XSS via persistence of subframes | $8,000 | 2016-10-02 |
| 557800 | Heap-use-after-free in autofill::FormStructure::ParseQueryResponse | - | 2016-10-02 |
| 556351 | Crash in password_manager::ContentPasswordManagerDriver::OnPasswordFormsParsed | - | 2016-10-02 |
| 556584 | Heap-use-after-free in content::MemoryMessageFilter::OnChannelClosing | - | 2016-10-02 |
| 574802 | ASSERTION FAILED: index < arraySize | $3,000 | 2016-10-02 |
| 574114 | Use-of-uninitialized-value in S32A_Opaque_BlitRow32_SSE4 | $1,000 | 2016-10-02 |
| 573332 | Heap-buffer-overflow in xmlParseXMLDecl | - | 2016-10-02 |
| 573317 | UX and Extensions API confusion when file: URLs have hostnames | $500 | 2016-10-02 |
| 573284 | Heap-buffer-overflow in blink::TimerBase::stop | $3,500 | 2016-10-02 |
| 573281 | Heap-use-after-free in blink::InlineWalker::InlineWalker | - | 2016-10-02 |
| 572871 | Security: PureCall on CPWL_Edit::OnKillFocus | $3,000 | 2016-10-02 |
| 573886 | Heap-use-after-free in extensions::MimeHandlerViewContainer::DidFinishLoading | - | 2016-10-02 |
| 572409 | Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer | - | 2016-10-02 |
| 572408 | Use-of-uninitialized-value in v8::internal::compiler::VirtualState::MergeFrom | - | 2016-10-02 |
| 572407 | Heap-use-after-free in blink::Node::assignedSlot | - | 2016-10-02 |
| 572406 | Use-of-uninitialized-value in winding_mono_conic | - | 2016-10-02 |
| 572404 | Heap-use-after-free in ash::WindowSelector::ContentsChanged | $1,000 | 2016-10-02 |
| 572537 | Security: heap-use-after-free in blink::NodeIteratorBase::root | $3,000 | 2016-10-02 |
| 572403 | Heap-buffer-overflow in SkARGB32_Opaque_Blitter::blitAntiH2 | - | 2016-10-02 |
| 572398 | Heap-use-after-free in content::WebMediaPlayerMSCompositor::StopRenderingInternal | - | 2016-10-02 |
| 572224 | UNKNOWN in extensions::WebrtcAudioPrivateFunction::CalculateHMACImpl | $1,000 | 2016-10-02 |
| 571480 | ZDI-CAN-3447: New Vulnerability Report Google Chrome Pdfium JPEG2000 Out-Of-Bounds Read Remote Code Execution Vulnerability | - | 2016-10-02 |
| 571479 | ZDI-CAN-3432: New Vulnerability Report | - | 2016-10-02 |
| 571121 | Security: Devtools loads any URL with remoteBase parameter | - | 2016-10-02 |
| 571617 | Security: dev-tools: URIs can be copy&paste'd | - | 2016-10-02 |
| 570750 | Security: Android Chrome download files into arbitrary sdcard directory | $500 | 2016-10-02 |
| 570618 | Vulnerability reported in dev-libs/libxml2 | - | 2016-10-02 |
| 570561 | Bad-cast to const blink::LayoutBox from blink::LayoutInline;LayoutBox.h:1001:1 | - | 2016-10-02 |
| 570427 | UaF in blink::SearchInputType::didSetValueByUserEdit | - | 2016-10-02 |
| 570262 | Crash in v8::internal::Invoke | - | 2016-10-02 |
| 571119 | Security: Extensions can open privileged URLs using tabs URL | - | 2016-10-02 |
| 570261 | Heap-buffer-overflow in sctp_setopt | - | 2016-10-02 |
| 570255 | Heap-buffer-overflow: LayoutObject should have height even if it is placed very far place | - | 2016-10-02 |
| 570241 | Stack-buffer-underflow in v8::internal::QuickCheckDetails::Advance | - | 2016-10-02 |
| 569956 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
| 569940 | Stack-buffer-underflow in v8::internal::Trace::AdvanceCurrentPositionInTrace | - | 2016-10-02 |
| 569496 | Security: Universal XSS using Flash message loop | $7,500 | 2016-10-02 |
| 569420 | Heap-use-after-free in cricket::ChannelManager::RemoveVideoRenderer | - | 2016-10-02 |
| 569170 | Heap-use-after-free in blink::ColorInputType::didChooseColor | - | 2016-10-02 |
| 569043 | onmouseenter/leave + ES6 on window leaks functions between origins | - | 2016-10-02 |
| 568889 | Stack-buffer-overflow in WebRtcIlbcfix_CreateAugmentedVec | - | 2016-10-02 |
| 568885 | Stack-buffer-overflow in WebRtcSpl_ElementwiseVectorMult | - | 2016-10-02 |
| 569284 | Heap-use-after-free in blink::Node::assignedSlot | - | 2016-10-02 |
| 568796 | Use-after-poison in blink::OfflineAudioContext::resolveSuspendOnMainThread | - | 2016-10-02 |
| 568745 | Use-of-uninitialized-value in void base::Pickle::WriteBytesStatic<4ul> | - | 2016-10-02 |
| 568742 | Heap-buffer-overflow in gpu::gles2::GLES2Implementation::TexImage2D | - | 2016-10-02 |
| 568741 | Use-of-uninitialized-value in re2::NFA::AddToThreadq | - | 2016-10-02 |
| 568433 | Heap-use-after-free in content::IndexedDBBackingStore::Transaction::ChainedBlobWriterImpl::ReportWriteC | $5,500 | 2016-10-02 |
| 567956 | adobe.com is (incorrectly) reporting out of date Flash plugin | - | 2016-10-02 |
| 568797 | Heap-use-after-free in content::RenderWidgetHostImpl::ScheduleComposite | - | 2016-10-02 |
| 568744 | Heap-use-after-free in blink::ShapeOutsideInfo::isEnabledFor | - | 2016-10-02 |
| 584223 | Heap-buffer-overflow in cmsDupNamedColorList | - | 2016-10-02 |
| 584185 | Security: Heap-use-after-free in blink::LayoutObject::parent | - | 2016-10-02 |
| 583563 | Heap-buffer-overflow in ConvertWOFF2ToTTF | $1,000 | 2016-10-02 |
| 583445 | UXSS in DocumentLoader::createWriterFor | - | 2016-10-02 |
| 583354 | Crash in ff_get_qtpalette | - | 2016-10-02 |
| 583171 | Security: Memory leak in libxslt | $1,000 | 2016-10-02 |
| 583156 | Security: Type confusion and UAF in libxslt | $1,000 | 2016-10-02 |
| 583718 | Heap-use-after-free in favicon::FaviconDriverImpl::DidDownloadFavicon | $500 | 2016-10-02 |
| 584155 | Security: General bypass of SRI validation for subresources located on the same origin | $2,000 | 2016-10-02 |
| 583607 | Security: Buffer overflow in Brotli decompression | $1,000 | 2016-10-02 |
| 582716 | Heap-buffer-overflow in vp9_update_noise_estimate | - | 2016-10-02 |
| 582721 | Use-of-uninitialized-value in SkUnPreMultiply::PMColorToColor | - | 2016-10-02 |
| 582713 | Use-after-poison in blink::WebGLObject::detach | - | 2016-10-02 |
| 583039 | Use-of-uninitialized-value in xmlCurrentChar | - | 2016-10-02 |
| 583041 | Use-of-uninitialized-value in xmlNextChar | - | 2016-10-02 |
| 582705 | Negative-size-param in SkRBufferWithSizeCheck::read | - | 2016-10-02 |
| 582703 | Crash in v8::internal::Runtime_FunctionGetScript | - | 2016-10-02 |
| 582710 | Bad-cast to blink::ContextLifecycleObserver from invalid vptr;DOMTimer.cpp:140:9 | - | 2016-10-02 |
| 582701 | Crash in blink::AudioParamTimeline::valuesForFrameRangeImpl | - | 2016-10-02 |
| 582700 | Bad-cast to blink::LayoutBox from blink::LayoutInline;LayoutBox.h:1001:1 | - | 2016-10-02 |
| 582699 | Crash (assert) in blink::AudioDelayDSPKernel::process | $1,500 | 2016-10-02 |
| 582707 | Crash in chrome | - | 2016-10-02 |
| 582706 | ASSERTION FAILED: !object || (object->isLayoutBlock()) | - | 2016-10-02 |
| 582702 | Crash in v8::internal::compiler::InstructionSequence::GetRepresentation | - | 2016-10-02 |
| 582695 | Heap-buffer-overflow in gpu::gles2::GLES2Implementation::TexImage2D | - | 2016-10-02 |
| 582480 | Use-of-uninitialized-value in icuLikeCompare | - | 2016-10-02 |
| 582471 | Use-of-uninitialized-value in WebRtcIsac_DecLogisticMulti2 | - | 2016-10-02 |
| 582470 | Use-of-uninitialized-value in icu_54::RegexCompile::doParseActions | - | 2016-10-02 |
| 582211 | With --site-per-process, body of POST request is not delivered to XSSAuditor | - | 2016-10-02 |
| 582698 | ASSERTION FAILED: !object || (object->isTableRow()) | - | 2016-10-02 |
| 582697 | ASSERTION FAILED: !object || (object->isBox()) | - | 2016-10-02 |
| 581905 | Use-of-uninitialized-value in xmlGROW | - | 2016-10-02 |
| 582008 | Heap-use-after-free when a content script synchronously removes a frame at document_start or document_end | $1,500 | 2016-10-02 |
| 581839 | Use-of-uninitialized-value in xmlParserPrintFileContextInternal | - | 2016-10-02 |
| 581836 | Use-of-uninitialized-value in xmlParseComment | - | 2016-10-02 |
| 581294 | Vulnerability reported in libpng | - | 2016-10-02 |
| 581908 | Security: Master tracking bug for chrome issue tracker libvpx fixes (January 2016) | - | 2016-10-02 |
| 581901 | Use-of-uninitialized-value in WebRtcIsacfix_AllpassFilter2FixDec16C | - | 2016-10-02 |
| 578193 | Heap-buffer-overflow in webrtc::VP9EncoderImpl::GetEncodedLayerFrame | - | 2016-10-02 |
| 577105 | Security: Universal XSS by circumventing the unload event | $7,500 | 2016-10-02 |
| 579801 | Security: CSP isn't applied to Service Workers in Chrome | $1,000 | 2016-10-02 |
| 577970 | ClientSideDetectionHost::OnPhishingDetectionDone never get called | - | 2016-10-02 |
| 580181 | Security: Reproducible tab crash when opening inspector due to DOM object corruption via marquee tag in svg | - | 2016-10-02 |
| 576867 | Security: Google Chrome <any version> Extensions Web Accessible Resources Bypass | $500 | 2016-10-02 |
| 576383 | Security: UaF in MidiHost round 2 (JS -> Browser code execution) | - | 2016-10-02 |
| 575220 | Heap-buffer-overflows in sqlite3 when REGEXP keyword is used | - | 2016-10-02 |
| 575206 | Heap-buffer-overflow in icu_54::RegexCompile::nextCharLL | - | 2016-10-02 |
| 575205 | Heap-buffer-overflow in icuLikeCompare (called from sqlite3_step) | - | 2016-10-02 |
| 576910 | Crash in SkRBufferWithSizeCheck::read | - | 2016-10-02 |
| 576908 | Heap-buffer-overflow in SkPaint::unflatten | - | 2016-10-02 |
| 590118 | Security: Universal XSS using an intercepted native function | $7,500 | 2016-10-02 |
| 589848 | Heap-use-after-free in FT_New_Size | $3,000 | 2016-10-02 |
| 589838 | Security: type confusion in blink::BaseButtonInputType::valueAttributeChanged | $5,000 | 2016-10-02 |
| 589792 | Security: [v8] Out of bound(??) memory write with asm.js | $5,000 | 2016-10-02 |
| 589512 | Use-of-uninitialized-value in ebml_read_num | $1,500 | 2016-10-02 |
| 589237 | Security: HTTP 302 can navigate to non-web-accessible chrome-extension:// URIs | - | 2016-10-02 |
| 589186 | Security: use after free in memory-only disk cache | - | 2016-10-02 |
| 590247 | Security: use-after-poison in blink::PersistentBase with FileSystemSync in a Shared Worker | $3,500 | 2016-10-02 |
| 590284 | Security: RWHI UaF from bad fullscreen widget routing id | $10,500 | 2016-10-02 |
| 588711 | Security: chrome canary chrome_child!blink::LayoutTableSection::layout UAF bug | - | 2016-10-02 |
| 588566 | Crash in blink::DocumentThreadableLoader::cancelWithError | - | 2016-10-02 |
| 588862 | Security: kernel CVE-2016-2384: arbitrary code execution due to a double-free in the usb-midi linux kernel driver | - | 2016-10-02 |
| 588552 | Heap-use-after-free in blink::DepthOrderedLayoutObjectList::ordered | - | 2016-10-02 |
| 588550 | Heap-use-after-free in blink::CanvasAsyncBlobCreator::createBlobAndCall | $3,500 | 2016-10-02 |
| 588548 | LayoutText::setTextWithOffset() should handle ::first-letter | - | 2016-10-02 |
| 587897 | Update libxml to 2.9.3 or latest | - | 2016-10-02 |
| 587852 | Use-of-uninitialized-value in WebRtcIsac_DecLogisticMulti2 | - | 2016-10-02 |
| 588200 | Global-buffer-overflow in XFA_FM_KeywordToString | - | 2016-10-02 |
| 587227 | ZDI-CAN-3563: New Vulnerability Report | - | 2016-10-02 |
| 586798 | Heap-use-after-free in ASN1_STRING_free | - | 2016-10-02 |
| 586820 | Security: Timing attack on SVG feComposite filter circumvents same-origin policy | - | 2016-10-02 |
| 586765 | Security: ASSERTION FAILED: obj->isLayoutInline() || obj == this in blink::LayoutBlockFlow::createLineBoxes | - | 2016-10-02 |
| 586800 | Use-of-uninitialized-value in lh_retrieve | - | 2016-10-02 |
| 586657 | Directory traversal on file:// via escaped slashes | $500 | 2016-10-02 |
| 586494 | Security: heap-use-after-free in blink::LayoutObject::parent | - | 2016-10-02 |
| 586722 | Heap-use-after-free in blink::LayoutObject::markContainerChainForPaintInvalidation | - | 2016-10-02 |
| 586720 | Heap-use-after-free in blink::InlineFlowBox::addToLine | $3,500 | 2016-10-02 |
| 586721 | Heap-use-after-free in blink::PaintArtifact::appendToWebDisplayItemList | - | 2016-10-02 |
| 586079 | Heap-buffer-overflow in sqlite3VdbeMemSetStr | - | 2016-10-02 |
| 585707 | Heap-use-after-free in media::GpuMemoryBufferVideoFramePool::PoolImpl::GetOrCreateFrameResources | - | 2016-10-02 |
| 585704 | Bad-cast to blink::LayoutBox from blink::LayoutInline;LayoutBox.h:1045:1 | - | 2016-10-02 |
| 586266 | Security: heap-use-after-free in blink::LayoutObject::LayoutObjectBitfields::selfNeedsLayout | $3,000 | 2016-10-02 |
| 585698 | Use-of-uninitialized-value in SkUnPreMultiply::PMColorToColor | - | 2016-10-02 |
| 585701 | LayoutText::previousOffsetForBackwardDeletion() should consider first-letter | - | 2016-10-02 |
| 585595 | Heap-use-after-free in scheduler::internal::TaskQueueImpl::GetTimeDomain | - | 2016-10-02 |
| 585282 | Restricted web APIs can easily be accessed from Chrome apps | $1,000 | 2016-10-02 |
| 585268 | Heap-use-after-free in LoadWatcher::CallbackAndDie (chrome.app.window.create) | $2,000 | 2016-10-02 |
| 585699 | Use-of-uninitialized-value in blink::LayoutObject::containingBlock | - | 2016-10-02 |
| 585658 | Security: Upstream bug reported in NSS | - | 2016-10-02 |
| 595656 | Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer | $3,500 | 2016-10-02 |
| 595836 | libANGLE buffer-overflow (part of pwn2own exploit) | - | 2016-10-02 |
| 595514 | Security: Navigating to "chrome://" URLs inside pdf (iOS) | $500 | 2016-10-02 |
| 595339 | Security: Navigating to "chrome://" URLs and "file://" URLs via window.open() | $500 | 2016-10-02 |
| 595262 | Heap-buffer-overflow in xmlParseEndTag2 | - | 2016-10-02 |
| 595259 | Crash in v8::internal::StackFrameIterator::StackFrameIterator | $3,500 | 2016-10-02 |
| 594958 | Crash in v8::internal::MarkCompactMarkingVisitor::MarkObjectByPointer | - | 2016-10-02 |
| 594574 | Security: v8 Array.concat OOB access writeup | $7,500 | 2016-10-02 |
| 594512 | Use-of-uninitialized-value in Decode | - | 2016-10-02 |
| 594383 | Security: UXSS via window.open() via file:// pages | $3,000 | 2016-10-02 |
| 593759 | Security: Proxy Auto-Config SSL/TLS Url Disclosure | $500 | 2016-10-02 |
| 593690 | Use-of-uninitialized-value in xmlParseEndTag2 | - | 2016-10-02 |
| 594120 | Heap-use-after-free in FXJS_GetPrivate | $5,000 | 2016-10-02 |
| 592956 | Security: XSS on NTP | - | 2016-10-02 |
| 591785 | ZDI-CAN-3594: New Vulnerability Report | - | 2016-10-02 |
| 592361 | Use-of-uninitialized-value in v8::InstantiateModuleFromAsm | - | 2016-10-02 |
| 590882 | Chrome: Crash Report - gfx::Image::ToImageSkia | - | 2016-10-02 |
| 590801 | Use-of-uninitialized-value in blink::CSSParserToken::operator== | - | 2016-10-02 |
| 590620 | Heap-use-after-free in blink::FrameView::performLayout | $3,500 | 2016-10-02 |
| 590619 | Container-overflow in blink::HTMLMenuItemElement::defaultEventHandler | - | 2016-10-02 |
| 591402 | Tracking bug for internal fixes: Chrome M49, release 0 | - | 2016-10-02 |
| 590832 | Security: Lazy bailout from TurboFan after CompareIC is wrong | - | 2016-10-02 |
| 590615 | Heap-buffer-overflow in i2c_ASN1_INTEGER | - | 2016-10-02 |
| 590610 | Bad-cast to const blink::WebPasswordCredential from blink::WebCredential;credential_manager_content_utils.cc:26:9 | - | 2016-10-02 |
| 601801 | Security: Unsigned wraparound in a multiply in kbasep_vinstr_attach_client leads to a heap overflow. | - | 2016-10-02 |
| 601737 | content/ should destroy ImageDownloaderImpl() before shutting down Blink | - | 2016-10-02 |
| 601706 | Security: Universal XSS using a flaw in the load deferral logic | $7,500 | 2016-10-02 |
| 601629 | Security: Read access violation on same-origin, cross-process frames | $3,000 | 2016-10-02 |
| 601362 | Security: PDFium Out-of-Bounds Read in CFX_FaceCache::RenderGlyph | $1,000 | 2016-10-02 |
| 602046 | ZDI-CAN-3655: Google Chrome PDFium JPEG Out-Of-Bounds Read Information Disclosure Vulnerability | - | 2016-10-02 |
| 600977 | Use-of-uninitialized-value in webrtc::RTCPReceiver::HandleRPSI | - | 2016-10-02 |
| 601234 | Security: SDCH Get-Dictionary follows cross-domain redirects | - | 2016-10-02 |
| 600777 | Security: Merge bug for pdfium:419 | - | 2016-10-02 |
| 600735 | Heap-use-after-free in blink::LayoutObject::isAnonymousBlock | - | 2016-10-02 |
| 600953 | Global-buffer-overflow in WebRtcIsacfix_PitchFilterCore | - | 2016-10-02 |
| 600182 | Security: Universal XSS using deferred history loads | $7,500 | 2016-10-02 |
| 600671 | Use-of-uninitialized-value in base::Pickle::WriteData | - | 2016-10-02 |
| 599861 | Heap-use-after-free in blink::PaintLayer::removeChild | - | 2016-10-02 |
| 599855 | Use-of-uninitialized-value in blink::PaintLayerScrollableArea::invalidateAllStickyConstraints | - | 2016-10-02 |
| 599854 | Crash in sk_ssse3::blit_mask_d32_a8 | - | 2016-10-02 |
| 599849 | Heap-use-after-free in blink::LayoutBoxModelObject::invalidateStickyConstraints | $3,500 | 2016-10-02 |
| 599846 | Heap-buffer-overflow in media::AudioBuffer::ReadFrames | - | 2016-10-02 |
| 599866 | Heap-use-after-free LayoutBoxModelObject::continuation() (NO STACK) | - | 2016-10-02 |
| 599627 | Bad-cast to blink::LayoutBlock from blink::LayoutTableRow;LayoutBlock.h:515:1 | - | 2016-10-02 |
| 599625 | Heap-buffer-overflow in media::AudioBus::AudioBus | - | 2016-10-02 |
| 599458 | Use-of-uninitialized-value in sk_sse41::blit_row_s32a_opaque | - | 2016-10-02 |
| 599409 | Crash in v8::internal::Invoke | - | 2016-10-02 |
| 599081 | Security: GPU process BufferManager double-reads | - | 2016-10-02 |
| 599003 | RUNTIME_ASSERT in map->IsMap() in src/heap/spaces.cc | - | 2016-10-02 |
| 598848 | Crash in SkResizeFilter::computeFilters | - | 2016-10-02 |
| 598752 | kMainSRTDownloadURL is HTTP | $500 | 2016-10-02 |
| 598312 | Security: ChromeOS accepts ICMP redirects | - | 2016-10-02 |
| 598077 | Cross-Origin CSS Attack with Service Worker | $500 | 2016-10-02 |
| 598047 | Address bar not updated when returning from network error page. | - | 2016-10-02 |
| 597636 | Security: Possible double-reads in GPU command buffer code. | - | 2016-10-02 |
| 597625 | Security: GPU process MailboxManagerImpl double-reads | - | 2016-10-02 |
| 598165 | Security: Universal XSS via the interception of |Binding| with Object.prototype.create | $7,500 | 2016-10-02 |
| 597926 | Heap-buffer-overflow in SkOpContour::operand | $500 | 2016-10-02 |
| 597333 | CVE-2015-1805 Linux kernel: pipe: iovec overrun leading to memory corruption | - | 2016-10-02 |
| 596862 | Security: Block GPU Process Opening Renderer Processes | - | 2016-10-02 |
| 597518 | Tracking bug for internal fixes: Chrome M49, release 2 | - | 2016-10-02 |
| 597322 | Security: URL spoof + iframe spoof | $1,000 | 2016-10-02 |
| 597532 | Security: Universal XSS using a FrameNavigationDisabler bypass | $7,500 | 2016-10-02 |
| 606390 | Security: V8ValueConverter::ToV8Value is insecure (e.g. heap-use-after-free in MimeHandlerViewContainer::PostMessage | $3,500 | 2016-10-02 |
| 606185 | Heap-buffer-overflow in CopyAlphaChannelIntoVideoFrame | $1,000 | 2016-10-02 |
| 606181 | Security: Due to out of index of 'Node' object , attacker can control all contents of 'Node' object | $1,000 | 2016-10-02 |
| 606115 | Security: Use After Free in RegExp of V8 | $3,000 | 2016-10-02 |
| 605491 | Use-of-uninitialized-value in CPDF_TextPage::PreMarkedContent | - | 2016-10-02 |
| 605488 | Bad-cast to v8::internal::AstNode from invalid vptr;wasm-js.cc:138:7 | - | 2016-10-02 |
| 605480 | Heap-use-after-free in base::trace_event::BlameContext::Enter | - | 2016-10-02 |
| 605910 | Security: Universal XSS using iterables | $7,500 | 2016-10-02 |
| 605766 | Security: Universal XSS through adopting image elements | $8,000 | 2016-10-02 |
| 605470 | Crash in v8::internal::Invoke | $3,500 | 2016-10-02 |
| 605476 | Heap-use-after-free in extensions::ExtensionKeybindingRegistry::IsAcceleratorRegistered | - | 2016-10-02 |
| 604901 | Security: Persistent UXSS via SchemaRegistry | $7,500 | 2016-10-02 |
| 605474 | Bad-cast to net::QuicSpdySession from net::QuicSession;quic_spdy_stream.cc:41:3 | - | 2016-10-02 |
| 605451 | CSP 'referrer' directive ignored for preload requests | $500 | 2016-10-02 |
| 604897 | Compiled regexps execute incorrectly on function source strings | $1,000 | 2016-10-02 |
| 603748 | Security: Leak of extension privates via utils module | $1,000 | 2016-10-02 |
| 603725 | Security: Web pages can load arbitrary extension modules | $4,000 | 2016-10-02 |
| 603682 | Pinned TLS public keys (HPKP) evicted after clearing cache | $500 | 2016-10-02 |
| 603518 | Security: PDFium Out-of-Bounds Read in CPDF_DeviceCS::TranslateImageLine | $1,000 | 2016-10-02 |
| 603732 | Security: Heap-use-after-free via GCCallback | $3,000 | 2016-10-02 |
| 602970 | Security: type confusion lead to information leak in decodeURI | $7,500 | 2016-10-02 |
| 602975 | Use-of-uninitialized-value in woff2::ConvertWOFF2ToTTF | - | 2016-10-02 |
| 602697 | Tracking bug for internal fixes: Chrome M50, release 0 | - | 2016-10-02 |
| 602273 | Use-after-poison in blink::MediaStreamSource::setReadyState | - | 2016-10-02 |
| 602185 | Heap-buffer-overflow in fixup_vorbis_headers | - | 2016-10-02 |
| 602271 | Heap-use-after-free in blink::LayoutListItem::updateMarkerLocation | - | 2016-10-02 |
| 612364 | Security: Heap buffer overflow from unchecked length in mojo::edk::ports::Message::Parse | - | 2016-10-02 |
| 612132 | Security: Bypass CORS check by reopening XHRs | - | 2016-10-02 |
| 612023 | Heap-buffer-overflow in setup_frame_size_with_refs | - | 2016-10-02 |
| 612021 | Undefined-shift in vp9_parse_superframe_index | - | 2016-10-02 |
| 611887 | Security: Multiple vulnerabilities in mojo channel implementation | - | 2016-10-02 |
| 612049 | Heap-use-after-free in content::MediaStreamVideoSource::RemoveTrack | - | 2016-10-02 |
| 611352 | Heap-use-after-free in CFX_StringDataTemplate<wchar_t>::Retain() | $3,500 | 2016-10-02 |
| 610990 | Heap-use-after-free in blink::LayoutImage::styleDidChange | - | 2016-10-02 |
| 610989 | Heap-use-after-free in content::PermissionServiceImpl::CancelPendingOperations | - | 2016-10-02 |
| 610987 | Heap-use-after-free in v8::Isolate::VisitHandlesWithClassIds | $3,500 | 2016-10-02 |
| 610985 | Heap-use-after-free in blink::LayoutTextFragment::setTextFragment | - | 2016-10-02 |
| 610979 | Heap-use-after-free in blink::PrintContext::pageNumberForElement | - | 2016-10-02 |
| 610973 | Heap-use-after-free in std::__1::__tree_const_iterator<std::__1::__value_type<CFX_ByteString, CPDF_Obje | - | 2016-10-02 |
| 611782 | Heap-buffer-overflow in ReadScalar<unsigned | - | 2016-10-02 |
| 610966 | Heap-use-after-free in v8::internal::ElementsAccessorBase<v8::internal::TypedElementsAccessor< | - | 2016-10-02 |
| 610799 | Heap use after free in WorkerTarget::~WorkerTarget | - | 2016-10-02 |
| 610645 | Heap-buffer-overflow in SkAAClipBlitter::blitMask | - | 2016-10-02 |
| 610643 | Heap-use-after-free in blink::DeferredTaskHandler::handleDirtyAudioNodeOutputs | $3,500 | 2016-10-02 |
| 610600 | sandbox escape using ppapi broker | $15,000 | 2016-10-02 |
| 610646 | Bad-cast to const blink::WebPasswordCredential from blink::WebCredential;type_converters.cc:87:9 | - | 2016-10-02 |
| 610400 | Security: Bypass CORS using XHR and service workers | - | 2016-10-02 |
| 610441 | Security: Upgrade-Insecure-Requests does not perform Navigational Upgrades | - | 2016-10-02 |
| 610337 | Heap-buffer-overflow in epoll_add | - | 2016-10-02 |
| 609286 | extensions can bypass native messaging origin whitelisting | - | 2016-10-02 |
| 609260 | Security: heap-buffer-overflow in SkRegion::RunHead::findScanline | $1,000 | 2016-10-02 |
| 609134 | Crash in v8::Object::FindInstanceInPrototypeChain | - | 2016-10-02 |
| 609097 | Use-of-uninitialized-value in DetermineTextLanguage | - | 2016-10-02 |
| 608817 | Heap-use-after-free in blink::LayoutObject::containingBlock | $3,500 | 2016-10-02 |
| 608156 | Security: Heap-use-after-free in MessagingBindings::DispatchOnConnect | - | 2016-10-02 |
| 608104 | Security: Heap-use-after-free in RuntimeCustomBindings::GetExtensionViews | $1,500 | 2016-10-02 |
| 608101 | Security: Heap-use-after-free in autofill components | $1,000 | 2016-10-02 |
| 608100 | Security: Heap-use-after-free in AutofillAgent::FillFieldWithValue | $1,000 | 2016-10-02 |
| 607939 | Security: Devtools allows running privileged scripts via XSS on chrome-devtools-frontend.appspot.com | $3,500 | 2016-10-02 |
| 607921 | Security: Heap-use-after-free in ProfileInfoCache::SetAuthInfoOfProfileAtIndex | $1,000 | 2016-10-02 |
| 607722 | Heap-buffer-overflow in void v8::internal::String::WriteToFlat<unsigned short> | - | 2016-10-02 |
| 607721 | Use-of-uninitialized-value in woff2::ConvertWOFF2ToTTF | - | 2016-10-02 |
| 607652 | Tracking bug for internal fixes: Chrome M50, release 2 | - | 2016-10-02 |
| 607543 | An https iframe in an http page can use service worker | $1,000 | 2016-10-02 |
| 607483 | Security: Universal XSS converting IDL array/sequence values | - | 2016-10-02 |
| 618027 | Use-of-uninitialized-value in webrtc::H264::ParseRbsp | - | 2016-10-02 |
| 617997 | Crash in v8::internal::LargeObjectSpace::FindPage | - | 2016-10-02 |
| 618237 | Security: heap-use-after-free in getLineLayoutItem | $3,000 | 2016-10-02 |
| 617531 | Heap-buffer-overflow in webrtc::H264::ParseRbsp | - | 2016-10-02 |
| 617495 | Security: Universal XSS via same document navigations | $7,500 | 2016-10-02 |
| 617104 | Security: access-violation in blink::ScriptState::from | $1,000 | 2016-10-02 |
| 617635 | Crash in FixWinding | $3,500 | 2016-10-02 |
| 617536 | Use-of-uninitialized-value in webrtc::RtpDepacketizerH264::ProcessStapAOrSingleNalu | - | 2016-10-02 |
| 616970 | Heap-use-after-free in extensions::ExtensionKeybindingRegistry::IsAcceleratorRegistered | - | 2016-10-02 |
| 616488 | Security: web_accessible_resources can be bypassed when Chrome runs in a site isolation mode. | - | 2016-10-02 |
| 616386 | Security: Arbitrary Memory Read in v8 | $5,000 | 2016-10-02 |
| 616352 | Heap-buffer-overflow in blink::concatenateFamilyName | - | 2016-10-02 |
| 617097 | Heap-buffer-overflow in webrtc::RtpDepacketizerH264::ProcessStapAOrSingleNalu | - | 2016-10-02 |
| 615910 | upgrade-insecure-requests is not upgrading iframe sources | - | 2016-10-02 |
| 615820 | Heap-buffer-overflow in copy (in GURL::ReplaceComponents() ) | - | 2016-10-02 |
| 616119 | Heap-use-after-free in extensions::ConstructFileSystemList | - | 2016-10-02 |
| 614962 | AddressSanitizer: heap-buffer-overflow on address 0x7f4a13edc800 | $1,000 | 2016-10-02 |
| 614989 | Security: bypassing CORS by returning 308 for revalidating request for Resource previously without redirects from MemoryCache | - | 2016-10-02 |
| 614934 | Security: sfntly font parsing heap-buffer-overflow | $500 | 2016-10-02 |
| 614701 | Heap-buffer-overflow in setup_frame_size_with_refs | - | 2016-10-02 |
| 613915 | ASSERTION FAILED: i < m_len | - | 2016-10-02 |
| 613971 | Security: bypass CORS check by returning 304 from URL that previously returned 308 during revalidation from MemoryCache | - | 2016-10-02 |
| 613918 | Use-of-uninitialized-value in SkEvalCubicAt | - | 2016-10-02 |
| 614767 | Tracking bug for internal fixes: Chrome M51, release 0 | - | 2016-10-02 |
| 614405 | Security: update libxml to 2.9.4 | - | 2016-10-02 |
| 613905 | Crash in v8::base::NoBarrier_Load | - | 2016-10-02 |
| 613869 | Security: heap-use-after-free in blink::LayoutBox::shapeOutsideInfo | $3,000 | 2016-10-02 |
| 613698 | Security: mojo: Unchecked ports message payload lengths leading to buffer overflows and uafs | - | 2016-10-02 |
| 613626 | Credential Phishing via Transparent Authenticating Proxy Vector | $1,000 | 2016-10-02 |
| 613907 | Bad-cast to blink::LayoutObject from blink::PaintLayer;LayoutTableSection.cpp:831:18 | - | 2016-10-02 |
| 613607 | Global-buffer-overflow in XFA_GetMethodByName | - | 2016-10-02 |
| 613496 | Crash in v8::internal::Invoke | - | 2016-10-02 |
| 613488 | Crash in v8::internal::Invoke | - | 2016-10-02 |
| 613300 | Client-local parts of surface ID should be 64-bit and randomly generated | - | 2016-10-02 |
| 613266 | Security: Universal XSS via reentrancy in FrameLoader::startLoad | $7,500 | 2016-10-02 |
| 613160 | Security: Cisco Talos Security Advisory for Google chrome product - TALOS-CAN-0174 | $3,000 | 2016-10-02 |
| 612939 | Security: Wrong origin security indicators in Chrome Custom Tab | - | 2016-10-02 |
| 612613 | Security: Heap buffer overflows from unchecked payload_size in mojo::edj::BrokerHost::OnChannelMessage | - | 2016-10-02 |
| 612458 | Incorrect origin sent with message event in some cases | - | 2016-10-02 |
| 623186 | Crash in v8::internal::JavaScriptFrame::receiver | - | 2016-10-02 |
| 623193 | Stack-use-after-return in v8::internal::JsonStringifier::Result v8::internal::JsonStringifier::Serialize_< | - | 2016-10-02 |
| 623185 | Heap-buffer-overflow in content::WriteMemory | - | 2016-10-02 |
| 622522 | Security: unchecked size in mojo::Channel::Deserialize leads to memory corruption. | - | 2016-10-02 |
| 622351 | Bad-cast to v8::internal::PagedSpace from v8::internal::SemiSpace | - | 2016-10-02 |
| 622350 | Memcpy-param-overlap in CCodec_ProgressiveDecoder::GifReadMoreData | - | 2016-10-02 |
| 622664 | Stack-use-after-return in v8::internal::HandleBase::IsDereferenceAllowed | $3,500 | 2016-10-02 |
| 622183 | Security: Chrome Address Bar URL spoofing on IOS | $3,000 | 2016-10-02 |
| 621849 | Heap-use-after-free in cc::SurfaceManager::Destroy | - | 2016-10-02 |
| 621550 | Crash in v8::internal::StackTraceFrameIterator::Advance | - | 2016-10-02 |
| 621547 | Bad-cast to blink::BlobCallback from invalid vptr;void WTF::PartBoundFunctionImpl<;base::internal::Invoker<base::IndexSequence<0ul>, base::internal::BindState<base::internal::RunnableAdapter<void | - | 2016-10-02 |
| 622344 | Use-of-uninitialized-value in blink::Font::canShapeWordByWord | - | 2016-10-02 |
| 621115 | Use-of-uninitialized-value in blink::Font::canShapeWordByWord | - | 2016-10-02 |
| 621111 | Fatal error in v8::internal::List<T, P>::Add() | - | 2016-10-02 |
| 620949 | Security: Adobe Flash PSDK.Object Use After Free | $5,000 | 2016-10-02 |
| 620766 | Heap-use-after-free in cc::DrawPolygon::Split | - | 2016-10-02 |
| 620758 | Heap-buffer-overflow in epoll_add | - | 2016-10-02 |
| 620754 | Use-after-poison in blink::CrossThreadPersistentRegion::prepareForThreadStateTermination | - | 2016-10-02 |
| 620750 | Crash in v8::internal::Heap::AllocateHeapNumber | - | 2016-10-02 |
| 620694 | Incorrect packet size check leads to heap-buffer-overflow in pseudotcp | - | 2016-10-02 |
| 620553 | Security: V8 OOB Read(?) in GC with Array Object. | $5,000 | 2016-10-02 |
| 620737 | Security: Chrome does not distinguish between http and https proxies when saving passwords | - | 2016-10-02 |
| 620277 | Security: heap buffer overflow when calling RtpHeader::Parse on untrusted data | - | 2016-10-02 |
| 619405 | Security: Heap Buffer Overflow in opj_j2k_read_SQcd_SQcc | $3,500 | 2016-10-02 |
| 619382 | Use-of-uninitialized-value in long v8::internal::Simulator::AddWithCarry<long> | - | 2016-10-02 |
| 619380 | Use-of-uninitialized-value in blink::FloatingObject::unsafeClone | - | 2016-10-02 |
| 619378 | Crash in Sk4px::Load4 | - | 2016-10-02 |
| 619373 | Use-after-poison in blink::CrossThreadPersistentRegion::prepareForThreadStateTermination | - | 2016-10-02 |
| 619372 | Heap-buffer-overflow in usrsctp_dumppacket | - | 2016-10-02 |
| 619371 | Crash in SkAutoCanvasMatrixPaint::SkAutoCanvasMatrixPaint | - | 2016-10-02 |
| 619355 | Security: XSS issue in Google Mail | - | 2016-10-02 |
| 619006 | Security: Information leak in xsltFormatNumberConversion (libxslt) | $1,500 | 2016-10-02 |
| 618625 | Security: TSAN: data race in media::FFmpegDemuxer::~FFmpegDemuxer | $2,000 | 2016-10-02 |
| 609042 | Heap-buffer-overflow in Read | - | 2016-10-02 |