CVE-2016-1618
published 2016-01-25CVE-2016-1618: Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes…
PriorityP429medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.34%
68.5th percentile
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 47.0.2526.106 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-01-27·CVSS 7.6
CVE-2016-1612 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A bad cast was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via renderer crash or execute arbitrary code
with the privileges of the sandboxed render process. (CVE-2016-1612)
An issue was discovered when initializing the UnacceleratedImageBufferSurface
class in Blink. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2016-1614)
An issue was discovered with the CSP implementation in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to de
Red Hat
chromium-browser: weak random number generator in Blink
vendor_redhat·2016-01-20·CVSS 6.5
CVE-2016-1618 [MEDIUM] CWE-338 chromium-browser: weak random number generator in Blink
chromium-browser: weak random number generator in Blink
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
GHSA
GHSA-xjgv-3xxv-376h: Blink, as used in Google Chrome before 48
ghsa_unreviewed·2022-05-17
CVE-2016-1618 [MEDIUM] CWE-200 GHSA-xjgv-3xxv-376h: Blink, as used in Google Chrome before 48
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
OSV
oxide-qt vulnerabilities
osv·2016-01-27·CVSS 7.6
CVE-2016-1612 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A bad cast was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via renderer crash or execute arbitrary code
with the privileges of the sandboxed render process. (CVE-2016-1612)
An issue was discovered when initializing the UnacceleratedImageBufferSurface
class in Blink. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2016-1614)
An issue was discovered with the CSP implementation in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to determine whether specific HSTS sites had been
visited by rea
OSV
CVE-2016-1618: Blink, as used in Google Chrome before 48
osv·2016-01-22·CVSS 6.5
CVE-2016-1618 [MEDIUM] CVE-2016-1618: Blink, as used in Google Chrome before 48
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0072.htmlhttp://www.debian.org/security/2016/dsa-3456http://www.securityfocus.com/bid/81430http://www.securitytracker.com/id/1034801http://www.ubuntu.com/usn/USN-2877-1https://code.google.com/p/chromium/issues/detail?id=552749https://codereview.chromium.org/1419293005https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0072.htmlhttp://www.debian.org/security/2016/dsa-3456http://www.securityfocus.com/bid/81430http://www.securitytracker.com/id/1034801http://www.ubuntu.com/usn/USN-2877-1https://code.google.com/p/chromium/issues/detail?id=552749https://codereview.chromium.org/1419293005https://security.gentoo.org/glsa/201603-09
2016-01-25
Published