CVE-2016-5156 PUBLISHED

extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

EPSS 1.54% · 81.2th percentile

Risk Scores

EPSS Score
1.54%
81.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSoxide-qt1.12.7-0ubuntu0.14.04.1, 1.7.9-0ubuntu0.14.04.1, 1.8.4-0ubuntu0.14.04.2
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218
Ubuntu:14.04:LTSchromium-browser48.0.2564.116-0ubuntu0.14.04.1.1111, 29.0.1547.65-0ubuntu2, 31.0.1650.63-0ubuntu1~20131204.1
Ubuntu:16.04:LTSoxide-qt0, 1.9.5-0ubuntu1, 1.10.3-0ubuntu0.15.10.1

Timeline

References

Open in Interactive Console →