CVE-2016-5171 PUBLISHED

WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.

EPSS 0.84% · 74.6th percentile

Risk Scores

EPSS Score
0.84%
74.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSoxide-qt1.13.6-0ubuntu0.14.04.1, 1.8.4-0ubuntu0.14.04.2, 1.9.1-0ubuntu0.14.04.2
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.73-0ubuntu1.1218
Ubuntu:14.04:LTSchromium-browser48.0.2564.116-0ubuntu0.14.04.1.1111, 29.0.1547.65-0ubuntu2, 31.0.1650.63-0ubuntu1~20131204.1
Ubuntu:16.04:LTSoxide-qt0, 1.9.5-0ubuntu1, 1.10.3-0ubuntu0.15.10.1

Timeline

References

Open in Interactive Console →