CVE-2016-1684

18 documents9 sources
Severity
7.5HIGH
EPSS
0.9%
top 24.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 17

Description

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages3 packages

NVDgoogle/chrome50.0.2661.102
Debianlibxslt< 1.1.29-1+3
NVDxmlsoft/libxslt1.1.28

🔴Vulnerability Details

3
GHSA
GHSA-872f-6g3v-r884: numbers2022-05-17
OSV
CVE-2016-1684: numbers2016-06-05
CVEList
CVE-2016-1684: numbers2016-06-05

📋Vendor Advisories

10
Ubuntu
Libxslt vulnerabilities2017-04-28
Apple
CVE-2016-1684: watchOS 2.2.22016-07-18
Apple
CVE-2016-1684: iTunes 12.4.2 for Windows2016-07-18
Apple
CVE-2016-1684: iCloud for Windows 5.2.12016-07-18
Apple
CVE-2016-1684: tvOS 9.2.22016-07-18

💬Community

4
Bugzilla
CVE-2016-1684 CVE-2016-1683 mingw-libxslt: various flaws in libxslt [epel-7]2016-06-24
Bugzilla
CVE-2016-1684 CVE-2016-1683 mingw-libxslt: various flaws in libxslt [fedora-all]2016-06-24
Bugzilla
CVE-2016-1683 CVE-2016-1684 libxslt: various flaws [fedora-all]2016-06-24
Bugzilla
CVE-2016-1684 chromium-browser: integer overflow in libxslt2016-05-26
CVE-2016-1684 (HIGH CVSS 7.5) | numbers.c in libxslt before 1.1.29 | cvebase.io