Disclosed Chromium Security Bugs

Security: Accessibility of the chrome.webstorePrivate-API

#40094122Reporter: [Deleted User]
$0
10/1/2016

Security: Location bar spoofing when using replaceState in unload event handler

#40050368Reporter: mi...@chromium.org
$0
10/1/2016

Heap-buffer-overflow in Color32_SSE2

#40056603Reporter: aa...@google.com
$0
10/1/2016

OOB read with PDF in cell sorting

#40056982Reporter: sc...@gmail.com
$0
10/1/2016

Heap-use-after-free in WebCore::Font::glyphDataAndPageForCharacter

#40061739Reporter: in...@chromium.org
$0
10/1/2016

Security: UXSS via com.android.browser.application_id Intent extra

#40064753Reporter: we...@gmail.com
$500
10/1/2016

Heap-use-after-free in WebCore::RenderBox::exclusionShapeOutsideInfo

#40077397Reporter: in...@chromium.org
$0
10/1/2016

UNKNOWN in cssyyparse

#40077454Reporter: in...@chromium.org
$0
10/1/2016

ASSERTION FAILED: !value || value->isPrimitiveValue(), UNKNOWN in WebCore::StylePropertySerializer::getLayeredShorthandValue

#40077539Reporter: in...@chromium.org
$0
10/1/2016

ASSERT: isDocumentLifecycleObserver()ASAN:SIGSEGV, UNKNOWN in WebCore::DocumentLifecycleNotifier::notifyDocumentWasDisposed

#40077973Reporter: cl...@chromium.org
$0
10/1/2016
Showing 9141-9150 of 13102 bugs