CVE-2016-1654Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
2.5%
top 14.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 14

Description

The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDgoogle/chrome49.0.2623.112
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Linux Enterprise 12.0, Ubuntu Linux 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-2prq-w3xp-938f: The media subsystem in Google Chrome before 502022-05-14
CVEList
CVE-2016-1654: The media subsystem in Google Chrome before 502016-04-18
OSV
CVE-2016-1654: The media subsystem in Google Chrome before 502016-04-18

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-04-27
Red Hat
chromium-browser: uninitialized memory read in media2016-04-13

💬Community

1
Bugzilla
CVE-2016-1654 chromium-browser: uninitialized memory read in media2016-04-14
CVE-2016-1654 — Improper Input Validation in Google | cvebase