Vulnerability Name: | CVE-2016-1658 (CCN-112164) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-04-13 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2016-04-13 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||||||||||||||||||||||||||
Summary: | The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 CWE-284 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-1658 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html Source: SUSE Type: Third Party Advisory SUSE-SU-2016:1060 Source: SUSE Type: Third Party Advisory openSUSE-SU-2016:1061 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:1135 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:1136 Source: CCN Type: RHSA-2016-0638 Important: chromium-browser security update Source: REDHAT Type: UNKNOWN RHSA-2016:0638 Source: DEBIAN Type: Third Party Advisory DSA-3549 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/1658913002 Source: CONFIRM Type: UNKNOWN https://crbug.com/573317 Source: XF Type: UNKNOWN google-chrome-cve20161658-info-disc(112164) Source: GENTOO Type: UNKNOWN GLSA-201605-02 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-1658 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |