cbcvebase.
CVE-2016-1699
published 2016-06-05

CVE-2016-1699: WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not…

medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
googlechrome<= 51.0.2704.63
opensuseleap
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation
suselinux_enterprise

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv8.8HIGH