CVE-2016-5170 PUBLISHED

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Indexed Database (aka IndexedDB) API calls.

EPSS 0.84% · 74.6th percentile

Risk Scores

EPSS Score
0.84%
74.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSoxide-qt1.0.5-0ubuntu0.14.04.1, 1.1.2-0ubuntu0.14.04.1, 1.2.5-0ubuntu0.14.04.1
Ubuntu:14.04:LTSchromium-browser48.0.2564.116-0ubuntu0.14.04.1.1111, 29.0.1547.65-0ubuntu2, 31.0.1650.63-0ubuntu1~20131204.1
Ubuntu:16.04:LTSoxide-qt1.17.7-0ubuntu0.16.04.1, 1.11.4-0ubuntu1, 1.11.5-0ubuntu1
Ubuntu:16.04:LTSchromium-browser45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218, 47.0.2526.106-0ubuntu1.1221

Timeline

References

Open in Interactive Console →