VDB
CVE-2016-5207
CVE-2016-5207
PUBLISHED
CVSS 6.099999904632568 MEDIUM
In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.
EPSS 2.60% · 84.1th percentile
Risk Scores
CVSS 3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
2.60%
84.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | chromium-browser | 49.0.2623.87-0ubuntu0.14.04.1.1112, 47.0.2526.106-0ubuntu0.14.04.1.1107, 43.0.2357.81-0ubuntu0.14.04.1.1089 |
| Ubuntu:14.04:LTS | oxide-qt | 1.17.7-0ubuntu0.14.04.1, 1.17.9-0ubuntu0.14.04.1, 1.18.3-0ubuntu0.14.04.1 |
| Ubuntu:16.04:LTS | oxide-qt | 1.15.7-0ubuntu0.16.04.1, 1.13.6-0ubuntu1, 1.11.3-0ubuntu3 |
| Ubuntu:16.04:LTS | chromium-browser | 0, 48.0.2564.116-0ubuntu1.1229, 47.0.2526.106-0ubuntu1.1221 |
Timeline
- Dec 2, 2016 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Nov 30, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2016-5207 third-party-advisory
- https://googlechromereleases.blogspot.com/2016/12/stable-channel-update-for-desktop.html third-party-advisory
- https://ubuntu.com/security/notices/USN-3153-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-5207 third-party-advisory