CVE-2016-5170
chromium-browser: use after free in blink
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Indexed Database (aka IndexedDB) API calls.
WebKit/Source/bendengs/modules/v8/V8BendengForModules.cpp en Blink, como se usa en Google Chrome en versiones anteriores a 53.0.2785.113, no considera correctamente los efectos secundarios de los captadores durante la conversión de clave del array, lo que permite a atacantes remotos provocar una denegación de servicio (uso después de liberación de memoria) o tener otro posible impacto no especificado a través de llamadas API Indexed Database (también conocido como IndexedDB).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-31 CVE Reserved
- 2016-09-16 CVE Published
- 2024-05-13 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/92942 | Vdb Entry | |
http://www.securitytracker.com/id/1036826 | Vdb Entry | |
https://codereview.chromium.org/2332003002 | X_refsource_confirm | |
https://crbug.com/641101 | X_refsource_confirm | |
https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2016-1905.html | 2023-11-07 | |
http://www.debian.org/security/2016/dsa-3667 | 2023-11-07 | |
https://security.gentoo.org/glsa/201610-09 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-5170 | 2016-09-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1375863 | 2016-09-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 53.0.2785.101 Search vendor "Google" for product "Chrome" and version " <= 53.0.2785.101" | - |
Affected
|