Vulnerability Name: | CVE-2016-1677 (CCN-113445) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-05-25 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2016-05-25 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion." | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-1677 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html Source: SUSE Type: Third Party Advisory openSUSE-SU-2016:1430 Source: SUSE Type: Third Party Advisory openSUSE-SU-2016:1433 Source: SUSE Type: Third Party Advisory openSUSE-SU-2016:1496 Source: CCN Type: RHSA-2016-1190 Important: chromium-browser security update Source: DEBIAN Type: Third Party Advisory DSA-3590 Source: BID Type: UNKNOWN 90876 Source: CCN Type: BID-90876 Google Chrome Prior to 51.0.2704.63 Multiple Security Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1035981 Source: UBUNTU Type: Third Party Advisory USN-2992-1 Source: REDHAT Type: Third Party Advisory RHSA-2016:1190 Source: CONFIRM Type: Issue Tracking https://codereview.chromium.org/1936083002 Source: CONFIRM Type: Permissions Required https://crbug.com/602970 Source: XF Type: UNKNOWN google-chrome-cve20161677-code-exec(113445) Source: GENTOO Type: UNKNOWN GLSA-201607-07 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-1677 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |