CVE-2016-5164 PUBLISHED

Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML into the Developer Tools (aka DevTools) subsystem via a crafted web site, aka "Universal XSS (UXSS)."

EPSS 0.41% · 61.4th percentile

Risk Scores

EPSS Score
0.41%
61.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser0, 52.0.2743.116-0ubuntu0.16.04.1.1250, 51.0.2704.79-0ubuntu0.16.04.1.1242
Ubuntu:14.04:LTSchromium-browser40.0.2214.94-0ubuntu0.14.04.1.1068, 40.0.2214.111-0ubuntu0.14.04.1.1069, 41.0.2272.76-0ubuntu0.14.04.1.1076
Ubuntu:16.04:LTSoxide-qt1.16.5-0ubuntu0.16.04.1, 0, 1.9.5-0ubuntu1
Ubuntu:14.04:LTSoxide-qt1.12.6-0ubuntu0.14.04.1, 1.12.7-0ubuntu0.14.04.1, 1.13.6-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →