Chrome 55

55.0.2883.75 にSecurity Patchが36個含まれる模様。

[664411] High CVE-2016-9651: Private property access in V8. Credit to Guang Gong of Alpha Team Of Qihoo 360
[658535] High CVE-2016-5208: Universal XSS in Blink. Credit to Mariusz Mlynski
[655904] High CVE-2016-5207: Universal XSS in Blink. Credit to Mariusz Mlynski
[653749] High CVE-2016-5206: Same-origin bypass in PDFium. Credit to Rob Wu (robwu.nl)
[646610] High CVE-2016-5205: Universal XSS in Blink. Credit to Anonymous
[630870] High CVE-2016-5204: Universal XSS in Blink. Credit to Mariusz Mlynski
[664139] High CVE-2016-5209: Out of bounds write in Blink. Credit to Giwan Go of STEALIEN
[644219] High CVE-2016-5203: Use after free in PDFium. Credit to Anonymous
[654183] High CVE-2016-5210: Out of bounds write in PDFium. Credit to Ke Liu of Tencent’s Xuanwu LAB
[653134] High CVE-2016-5212: Local file disclosure in DevTools. Credit to Khalil Zhani
[649229] High CVE-2016-5211: Use after free in PDFium. Credit to Anonymous
[652548] High CVE-2016-5213: Use after free in V8. Credit to Khalil Zhani
[601538] Medium CVE-2016-5214: File download protection bypass. Credit to Jonathan Birch and MSVR
[653090] Medium CVE-2016-5216: Use after free in PDFium. Credit to Anonymous
[619463] Medium CVE-2016-5215: Use after free in Webaudio. Credit to Looben Yang
[654280] Medium CVE-2016-5217: Use of unvalidated data in PDFium. Credit to Rob Wu (robwu.nl)
[660498] Medium CVE-2016-5218: Address spoofing in Omnibox. Credit to Abdulrahman Alqabandi (@qab)
[657568] Medium CVE-2016-5219: Use after free in V8. Credit to Rob Wu (robwu.nl)
[660854] Medium CVE-2016-5221: Integer overflow in ANGLE. Credit to Tim Becker of ForAllSecure
[654279] Medium CVE-2016-5220: Local file access in PDFium. Credit to Rob Wu (robwu.nl)
[657720] Medium CVE-2016-5222: Address spoofing in Omnibox. Credit to xisigr of Tencent’s Xuanwu Lab
[653034] Low CVE-2016-9650: CSP Referrer disclosure. Credit to Jakub Żoczek
[652038] Low CVE-2016-5223: Integer overflow in PDFium. Credit to Hwiwon Lee
[639750] Low CVE-2016-5226: Limited XSS in Blink. Credit to Jun Kokatsu (@shhnjk)
[630332] Low CVE-2016-5225: CSP bypass in Blink. Credit to Scott Helme (@Scott_Helme, scotthelme.co.uk)
[615851] Low CVE-2016-5224: Same-origin bypass in SVG. Credit to Roeland Krak

カテゴリー: 未分類 パーマリンク

コメントを残す

メールアドレスが公開されることはありません。 が付いている欄は必須項目です