CVE-2016-1684 PUBLISHED

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.

EPSS 0.87% · 75.0th percentile

Risk Scores

EPSS Score
0.87%
75.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibxslt0, 1.1.28-2, 1.1.28-2build1
Ubuntu:16.04:LTSchromium-browser0, 50.0.2661.102-0ubuntu0.16.04.1.1237, 49.0.2623.108-0ubuntu1.1233
Ubuntu:16.04:LTSoxide-qt1.10.3-0ubuntu0.15.10.2, 1.10.3-0ubuntu0.15.10.1, 1.9.5-0ubuntu1
Ubuntu:14.04:LTSchromium-browser50.0.2661.102-0ubuntu0.14.04.1.1117, 47.0.2526.106-0ubuntu0.14.04.1.1107, 29.0.1547.65-0ubuntu2
Ubuntu:14.04:LTSoxide-qt0, 1.10.3-0ubuntu0.14.04.1, 1.11.3-0ubuntu0.14.04.1
Ubuntu:16.04:LTSlibxslt0, 1.1.28-2build2, 1.1.28-2.1

Timeline

References

Open in Interactive Console →