CVE-2016-1697
published 2016-06-05CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.85%
76.7th percentile
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| chrome | <= 51.0.2704.63 | — | |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-06-06·CVSS 8.8
CVE-2016-1673 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An unspecified security issue was discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1673)
An issue was discovered with Document reattachment in Blink in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to bypass same-origin
restrictions. (CVE-2016-1675)
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to obtain sensitive information. (CVE-2016-1677)
A heap overflow was discovered in V8. If a user wer
Red Hat
chromium-browser: cross-origin bypass in blink
vendor_redhat·2016-06-01·CVSS 8.8
CVE-2016-1697 [HIGH] chromium-browser: cross-origin bypass in blink
chromium-browser: cross-origin bypass in blink
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
GHSA
GHSA-gqhx-qf2x-9ggq: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader
ghsa_unreviewed·2022-05-14
CVE-2016-1697 [HIGH] CWE-284 GHSA-gqhx-qf2x-9ggq: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
OSV
CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader
osv·2016-06-06·CVSS 8.8
CVE-2016-1697 [HIGH] CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
OSV
oxide-qt vulnerabilities
osv·2016-06-06·CVSS 8.8
CVE-2016-1673 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An unspecified security issue was discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1673)
An issue was discovered with Document reattachment in Blink in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to bypass same-origin
restrictions. (CVE-2016-1675)
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to obtain sensitive information. (CVE-2016-1677)
A heap overflow was discovered in V8. If a user were tricked in to opening
a specially crafted website, an att
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10140 zoneminder: Information disclosure and authentication bypass
bugzilla·2017-01-17·CVSS 7.5
CVE-2016-10140 [HIGH] CVE-2016-10140 zoneminder: Information disclosure and authentication bypass
CVE-2016-10140 zoneminder: Information disclosure and authentication bypass
Information disclosure and authentication bypass vulnerability exists
in the Apache HTTP Server configuration bundled with ZoneMinder
v1.30.0, which allows a remote unauthenticated attacker to browse all
directories in the web root, e.g., a remote unauthenticated attacker
can view all CCTV images on the server.
Upstream bug:
https://github.com/ZoneMinder/ZoneMinder/pull/1697
Discussion:
Created zoneminder tracking bugs for this issue:
Affects: fedora-all [bug 1413909]
---
Fedora 26/rawhide not affected. zoneminder has been retired from master because it is moving to RPM Fusion.
Fedora 25 not affected. zoneminder-1.28.1-6.fc25 has:
./etc/httpd/conf.d/zoneminder.conf: Options -Indexes +MultiViews +FollowSymL
Bugzilla
CVE-2016-1697 chromium-browser: cross-origin bypass in blink
bugzilla·2016-06-02·CVSS 8.8
CVE-2016-1697 [HIGH] CVE-2016-1697 chromium-browser: cross-origin bypass in blink
CVE-2016-1697 chromium-browser: cross-origin bypass in blink
A cross-origin bypass flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=613266
External References:
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1201 https://access.redhat.com/errata/RHSA-2016:1201
Bugzilla
CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
bugzilla·2016-03-03·CVSS 5.7
CVE-2016-2116 [MEDIUM] CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
Memory leak in jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier was found, allowing remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
Vulnerable code:
src/libjasper/base/jas_icc.c:
1685 jas_iccprof_t *jas_iccprof_createfrombuf(uchar *buf, int len)
1686 {
1687 jas_stream_t *in;
1688 jas_iccprof_t *prof;
1689 if (!(in = jas_stream_memopen(JAS_CAST(char *, buf), len)))
1690 goto error;
1691 if (!(prof = jas_iccprof_load(in)))
1692 goto error;
1693 jas_stream_close(in);
1694 return prof;
1695 error:
1696 return 0;
1697 }
jas_stream_t allocated by the call to jas_stream_memopen() is leaked if jas_iccprof_load() fails on line 1691.
Prop
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3594http://www.securitytracker.com/id/1036026http://www.ubuntu.com/usn/USN-2992-1https://access.redhat.com/errata/RHSA-2016:1201https://codereview.chromium.org/2021373003https://crbug.com/613266http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3594http://www.securitytracker.com/id/1036026http://www.ubuntu.com/usn/USN-2992-1https://access.redhat.com/errata/RHSA-2016:1201https://codereview.chromium.org/2021373003https://crbug.com/613266
2016-06-05
Published