CVE-2016-0359
published 2016-07-03CVE-2016-0359: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty…
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.47%
70.9th percentile
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2844 chromium-browser: LayoutBlock.cpp in Blink does not properly determine when anonymous block wrappers may exist
bugzilla·2016-03-07·CVSS 8.8
CVE-2016-2844 [HIGH] CVE-2016-2844 chromium-browser: LayoutBlock.cpp in Blink does not properly determine when anonymous block wrappers may exist
CVE-2016-2844 chromium-browser: LayoutBlock.cpp in Blink does not properly determine when anonymous block wrappers may exist
It was reported that WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote attackers to cause a denial of service (incorrect cast and assertion failure) or possibly have unspecified other impact via crafted JavaScript code.
External Reference:
https://codereview.chromium.org/1423573002
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-2845 chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
bugzilla·2016-03-07·CVSS 5.3
CVE-2016-2845 [MEDIUM] CVE-2016-2845 chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
CVE-2016-2845 chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports.
External Reference:
https://codereview.chromium.org/1454003003/
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-2843 chromium-browser: Multiple unspecified vulnerabilities in V8 before 4.9.385.26
bugzilla·2016-03-07·CVSS 9.8
CVE-2016-2843 [CRITICAL] CVE-2016-2843 chromium-browser: Multiple unspecified vulnerabilities in V8 before 4.9.385.26
CVE-2016-2843 chromium-browser: Multiple unspecified vulnerabilities in V8 before 4.9.385.26
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75 was found, allowing attackers to cause a denial of service or possibly have other impact via unknown vectors.
External Reference:
http://googlechromereleases.blogspot.cz/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1637 chromium-browser: information leak in Skia
bugzilla·2016-03-03·CVSS 6.5
CVE-2016-1637 [MEDIUM] CVE-2016-1637 chromium-browser: information leak in Skia
CVE-2016-1637 chromium-browser: information leak in Skia
A information leak flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=555544
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1634 chromium-browser: use-after-free in Blink
bugzilla·2016-03-03·CVSS 8.8
CVE-2016-1634 [HIGH] CVE-2016-1634 chromium-browser: use-after-free in Blink
CVE-2016-1634 chromium-browser: use-after-free in Blink
A use-after-free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=559292
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1630 chromium-browser: same-origin bypass in Blink
bugzilla·2016-03-03·CVSS 8.8
CVE-2016-1630 [HIGH] CVE-2016-1630 chromium-browser: same-origin bypass in Blink
CVE-2016-1630 chromium-browser: same-origin bypass in Blink
A same-origin bypass flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=560011
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1636 chromium-browser: SRI Validation Bypass
bugzilla·2016-03-03·CVSS 9.8
CVE-2016-1636 [CRITICAL] CVE-2016-1636 chromium-browser: SRI Validation Bypass
CVE-2016-1636 chromium-browser: SRI Validation Bypass
An SRI Validation Bypass flaw was found in the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=584155
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1632 chromium-browser: bad cast in Extensions
bugzilla·2016-03-03·CVSS 8.8
CVE-2016-1632 [HIGH] CVE-2016-1632 chromium-browser: bad cast in Extensions
CVE-2016-1632 chromium-browser: bad cast in Extensions
A bad cast flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=549986
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1631 chromium-browser: same-origin bypass in Pepper Plugin
bugzilla·2016-03-03·CVSS 8.8
CVE-2016-1631 [HIGH] CVE-2016-1631 chromium-browser: same-origin bypass in Pepper Plugin
CVE-2016-1631 chromium-browser: same-origin bypass in Pepper Plugin
A same-origin bypass flaw was found in the Pepper Plugin component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=569496
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1641 chromium-browser: use-after-free in Favicon
bugzilla·2016-03-03·CVSS 8.8
CVE-2016-1641 [HIGH] CVE-2016-1641 chromium-browser: use-after-free in Favicon
CVE-2016-1641 chromium-browser: use-after-free in Favicon
A use-after-free flaw was found in the Favicon component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=583718
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1633 chromium-browser: use-after-free in Blink
bugzilla·2016-03-03·CVSS 9.8
CVE-2016-1633 [CRITICAL] CVE-2016-1633 chromium-browser: use-after-free in Blink
CVE-2016-1633 chromium-browser: use-after-free in Blink
A use-after-free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=572537
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1642 chromium-browser: various fixes from internal audits
bugzilla·2016-03-03·CVSS 9.8
CVE-2016-1642 [CRITICAL] CVE-2016-1642 chromium-browser: various fixes from internal audits
CVE-2016-1642 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=591402
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1635 chromium-browser: use-after-free in Blink
bugzilla·2016-03-03·CVSS 9.8
CVE-2016-1635 [CRITICAL] CVE-2016-1635 chromium-browser: use-after-free in Blink
CVE-2016-1635 chromium-browser: use-after-free in Blink
A use-after-free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=585268
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1639 chromium-browser: use-after-free in WebRTC
bugzilla·2016-03-03·CVSS 9.8
CVE-2016-1639 [CRITICAL] CVE-2016-1639 chromium-browser: use-after-free in WebRTC
CVE-2016-1639 chromium-browser: use-after-free in WebRTC
A use-after-free flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=572224
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1640 chromium-browser: origin confusion in Extensions UI
bugzilla·2016-03-03·CVSS 4.3
CVE-2016-1640 [MEDIUM] CVE-2016-1640 chromium-browser: origin confusion in Extensions UI
CVE-2016-1640 chromium-browser: origin confusion in Extensions UI
A origin confusion flaw was found in the Extensions UI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=550047
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
Bugzilla
CVE-2016-1638 chromium-browser: WebAPI Bypass
bugzilla·2016-03-03·CVSS 6.3
CVE-2016-1638 [MEDIUM] CVE-2016-1638 chromium-browser: WebAPI Bypass
CVE-2016-1638 chromium-browser: WebAPI Bypass
A WebAPI Bypass flaw was found in the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=585282
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
http://www-01.ibm.com/support/docview.wss?uid=swg1PI58918http://www-01.ibm.com/support/docview.wss?uid=swg21982526http://www.securityfocus.com/bid/91484http://www.securitytracker.com/id/1036184http://www-01.ibm.com/support/docview.wss?uid=swg1PI58918http://www-01.ibm.com/support/docview.wss?uid=swg21982526http://www.securityfocus.com/bid/91484http://www.securitytracker.com/id/1036184
2016-07-03
Published