cbcvebase.
CVE-2016-1661
published 2016-05-14

CVE-2016-1661: Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin…

PriorityP432high8CVSS 3.0
AVNACLPRLUIRSUCHIHAH
EPSS
1.24%
66.0th percentile
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site, related to BindingSecurity.cpp and DOMWindow.cpp.

Affected

6 ranges
VendorProductVersion rangeFixed in
googlechrome<= 50.0.2661.87
opensuseopensuse
redhatenterprise_linux_desktop_supplementary
redhatenterprise_linux_server_supplementary
redhatenterprise_linux_server_supplementary_eus
redhatenterprise_linux_workstation_supplementary

CVSS provenance

nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.