[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-1632Date: (C)2016-03-08   (M)2023-12-22


The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 6.8
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
-1035185
-84008
DSA-3507
GLSA-201603-09
SUSE-SU-2016:0665
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
https://code.google.com/p/chromium/issues/detail?id=549986
https://codereview.chromium.org/1433293004
openSUSE-SU-2016:0664
openSUSE-SU-2016:0684
openSUSE-SU-2016:0729

CPE    1
cpe:/a:google:chrome
CWE    1
CWE-264
OVAL    10
oval:org.secpod.oval:def:505297
oval:org.secpod.oval:def:33352
oval:org.secpod.oval:def:33351
oval:org.secpod.oval:def:33209
...

© SecPod Technologies