CVE-2016-5204 PUBLISHED

Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

EPSS 0.22% · 44.5th percentile

Risk Scores

EPSS Score
0.22%
44.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt1.16.5-0ubuntu0.16.04.1, 1.11.5-0ubuntu1, 1.12.7-0ubuntu1
Ubuntu:16.04:LTSchromium-browser47.0.2526.73-0ubuntu1.1218, 52.0.2743.116-0ubuntu0.16.04.1.1250, 51.0.2704.79-0ubuntu0.16.04.1.1242
Ubuntu:14.04:LTSoxide-qt1.16.5-0ubuntu0.14.04.1, 1.12.6-0ubuntu0.14.04.1, 1.18.5-0ubuntu0.14.04.1
Ubuntu:14.04:LTSchromium-browser0, 38.0.2125.111-0ubuntu0.14.04.1.1061, *

Timeline

References

Open in Interactive Console →