CVE-2016-1677 PUBLISHED

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

EPSS 12.63% · 93.9th percentile

Risk Scores

EPSS Score
12.63%
93.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt1.14.9-0ubuntu0.16.04.1, 1.14.7-0ubuntu1, 1.13.6-0ubuntu1
Ubuntu:14.04:LTSchromium-browser41.0.2272.76-0ubuntu0.14.04.1.1076, 43.0.2357.81-0ubuntu0.14.04.1.1089, 43.0.2357.130-0ubuntu0.14.04.1.1092
Ubuntu:16.04:LTSchromium-browser48.0.2564.116-0ubuntu1.1229, 0, 45.0.2454.101-0ubuntu1.1201
Ubuntu:18.04:LTSlibv8-3.143.14.5.8-11ubuntu1, 0
Ubuntu:14.04:LTSoxide-qt1.11.3-0ubuntu0.14.04.1, 1.11.4-0ubuntu0.14.04.1, 1.12.5-0ubuntu0.14.04.1
Ubuntu:16.04:LTSlibv8-3.143.14.5.8-5ubuntu2, 0

Timeline

References

Open in Interactive Console →