CVE-2016-1698
Severity
6.5MEDIUM
EPSS
0.6%
top 29.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 5
Latest updateMay 14
Description
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages7 packages
Also affects: Debian Linux 8.0, Linux Enterprise 12.0
🔴Vulnerability Details
3GHSA▶
GHSA-765m-xj9g-24vp: The createCustomType function in extensions/renderer/resources/binding↗2022-05-14
CVEList
▶
OSV
▶