CVE-2016-1690
published 2016-06-05CVE-2016-1690: The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame…
PriorityP429high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
1.04%
60.3th percentile
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 50.0.2661.102 | — | |
| chrome | <= 51.0.2704.63 | — | |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8jg-7vfp-8gwc: The Autofill implementation in Google Chrome before 51
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-1701 [HIGH] GHSA-c8jg-7vfp-8gwc: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
GHSA
GHSA-8x9h-cmjr-hprf: The Autofill implementation in Google Chrome before 51
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1690 [HIGH] GHSA-8x9h-cmjr-hprf: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
OSV
CVE-2016-1690: The Autofill implementation in Google Chrome before 51
osv·2016-06-05·CVSS 7.5
CVE-2016-1690 [HIGH] CVE-2016-1690: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
OSV
CVE-2016-1701: The Autofill implementation in Google Chrome before 51
osv·2016-06-05·CVSS 7.5
CVE-2016-1701 [HIGH] CVE-2016-1701: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
Red Hat
chromium-browser: use-after-free in autofill
vendor_redhat·2016-06-01·CVSS 7.5
CVE-2016-1701 [HIGH] chromium-browser: use-after-free in autofill
chromium-browser: use-after-free in autofill
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
Red Hat
chromium-browser: heap use-after-free in autofill
vendor_redhat·2016-05-25·CVSS 7.5
CVE-2016-1690 [HIGH] chromium-browser: heap use-after-free in autofill
chromium-browser: heap use-after-free in autofill
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1690 chromium-browser: heap use-after-free in autofill
bugzilla·2016-05-26·CVSS 7.5
CVE-2016-1690 [HIGH] CVE-2016-1690 chromium-browser: heap use-after-free in autofill
CVE-2016-1690 chromium-browser: heap use-after-free in autofill
A heap use-after-free flaw was found in the Autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=608100
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1190 https://access.redhat.com/errata/RHSA-2016:1190
Bugzilla
CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
bugzilla·2016-03-03·CVSS 5.7
CVE-2016-2116 [MEDIUM] CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
Memory leak in jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier was found, allowing remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
Vulnerable code:
src/libjasper/base/jas_icc.c:
1685 jas_iccprof_t *jas_iccprof_createfrombuf(uchar *buf, int len)
1686 {
1687 jas_stream_t *in;
1688 jas_iccprof_t *prof;
1689 if (!(in = jas_stream_memopen(JAS_CAST(char *, buf), len)))
1690 goto error;
1691 if (!(prof = jas_iccprof_load(in)))
1692 goto error;
1693 jas_stream_close(in);
1694 return prof;
1695 error:
1696 return 0;
1697 }
jas_stream_t allocated by the call to jas_stream_memopen() is leaked if jas_iccprof_load() fails on line 1691.
Prop
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3590http://www.securityfocus.com/bid/90876http://www.securitytracker.com/id/1035981https://access.redhat.com/errata/RHSA-2016:1190https://codereview.chromium.org/1960023002https://crbug.com/608100https://security.gentoo.org/glsa/201607-07http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3590http://www.securityfocus.com/bid/90876http://www.securitytracker.com/id/1035981https://access.redhat.com/errata/RHSA-2016:1190https://codereview.chromium.org/1960023002https://crbug.com/608100https://security.gentoo.org/glsa/201607-07
2016-06-05
Published