VYPR

Blink

by Google

CVEs (31)

  • CVE-2011-2337CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.

  • CVE-2011-1460CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.01

    WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.

  • CVE-2021-21128HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.07

    Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21203HigApr 26, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-6124HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

  • CVE-2018-17474HigNov 14, 2018
    risk 0.57cvss 8.8epss 0.01

    Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2016-5185HigDec 18, 2016
    risk 0.57cvss 8.8epss 0.01

    Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updateLifecyclePhasesInternal(), which allowed a remote attacker to perform an out of bounds memory read via crafted HTML pages.

  • CVE-2016-5182HigDec 18, 2016
    risk 0.57cvss 8.8epss 0.01

    Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, which allowed a remote attacker to potentially exploit heap corruption via crafted HTML pages.

  • CVE-2016-5171HigSep 25, 2016
    risk 0.57cvss 8.8epss 0.01

    WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted…

  • CVE-2016-5170HigSep 25, 2016
    risk 0.57cvss 8.8epss 0.01

    WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (use-after-free) or possibly…

  • CVE-2011-2335HigNov 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.

  • CVE-2011-1298HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.01

    An Integer Overflow exists in WebKit in Google Chrome before Blink M11 in the macOS WebCore::GraphicsContext::fillRect function.

  • CVE-2011-1803MedNov 12, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.

  • CVE-2011-1802MedNov 12, 2019
    risk 0.42cvss 6.5epss 0.01

    WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).

  • CVE-2011-2334MedNov 12, 2019
    risk 0.42cvss 6.5epss 0.00

    Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements with reflections.

  • CVE-2011-2336MedNov 7, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.

  • CVE-2011-2807MedNov 7, 2019
    risk 0.42cvss 6.5epss 0.00

    Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.

  • CVE-2011-2353MedNov 7, 2019
    risk 0.42cvss 6.5epss 0.01

    Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function.

  • CVE-2011-2808MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.

  • CVE-2011-1459MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.01

    The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.

Page 1 of 2