cbcvebase.

Redhat Enterprise Linux Workstation Supplementary vulnerabilities

86 known vulnerabilities affecting redhat/enterprise_linux_workstation_supplementary.

Total CVEs
86
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL22HIGH33MEDIUM30LOW1

Vulnerabilities

Page 5 of 5
CVE-2015-1285P4MEDIUMCVSS 5.0v6.02015-07-23
CVE-2015-1285 [MEDIUM] CWE-200 CVE-2015-1285: The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.
nvd
CVE-2014-3197P4MEDIUMCVSS 5.0v6.02014-10-08
CVE-2014-3197 [MEDIUM] CWE-264 CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2015-1286P4MEDIUMCVSS 4.3v6.02015-07-23
CVE-2015-1286 [MEDIUM] CWE-79 CVE-2015-1286: Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink "Universal XSS (UXSS)."
nvd
CVE-2015-1278P4MEDIUMCVSS 4.3v6.02015-07-23
CVE-2015-1278 [MEDIUM] CWE-254 CVE-2015-1278: content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensu content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.
nvd
CVE-2015-1287P4MEDIUMCVSS 4.3v6.02015-07-23
CVE-2015-1287 [MEDIUM] CWE-17 CVE-2015-1287: Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp.
nvd
CVE-2016-1664P4MEDIUMCVSS 4.3v6.02016-05-14
CVE-2016-1664 [MEDIUM] CWE-254 CVE-2016-1664: The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to spoof the address bar via a crafted web site.
nvd