[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-1658Date: (C)2016-04-28   (M)2023-12-22


The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 4.3CVSS Score : 4.3
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: LOWAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
DSA-3549
GLSA-201605-02
RHSA-2016:0638
SUSE-SU-2016:1060
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
https://codereview.chromium.org/1658913002
https://crbug.com/573317
openSUSE-SU-2016:1061
openSUSE-SU-2016:1135
openSUSE-SU-2016:1136

CPE    2
cpe:/o:debian:debian_linux:8.0
cpe:/a:google:chrome
CWE    1
CWE-200
OVAL    11
oval:org.secpod.oval:def:33994
oval:org.secpod.oval:def:505576
oval:org.secpod.oval:def:1800814
oval:org.secpod.oval:def:34026
...

© SecPod Technologies