CVE-2016-1701
published 2016-06-05CVE-2016-1701: The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame…
PriorityP432high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.95%
57.2th percentile
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 50.0.2661.102 | — | |
| chrome | <= 51.0.2704.63 | — | |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8jg-7vfp-8gwc: The Autofill implementation in Google Chrome before 51
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-1701 [HIGH] GHSA-c8jg-7vfp-8gwc: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
GHSA
GHSA-8x9h-cmjr-hprf: The Autofill implementation in Google Chrome before 51
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1690 [HIGH] GHSA-8x9h-cmjr-hprf: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
OSV
CVE-2016-1690: The Autofill implementation in Google Chrome before 51
osv·2016-06-05·CVSS 7.5
CVE-2016-1690 [HIGH] CVE-2016-1690: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
OSV
CVE-2016-1701: The Autofill implementation in Google Chrome before 51
osv·2016-06-05·CVSS 7.5
CVE-2016-1701 [HIGH] CVE-2016-1701: The Autofill implementation in Google Chrome before 51
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
Red Hat
chromium-browser: use-after-free in autofill
vendor_redhat·2016-06-01·CVSS 7.5
CVE-2016-1701 [HIGH] chromium-browser: use-after-free in autofill
chromium-browser: use-after-free in autofill
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
Red Hat
chromium-browser: heap use-after-free in autofill
vendor_redhat·2016-05-25·CVSS 7.5
CVE-2016-1690 [HIGH] chromium-browser: heap use-after-free in autofill
chromium-browser: heap use-after-free in autofill
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1516 opencv: Double free vulnerability on crafted image
bugzilla·2017-04-19·CVSS 8.8
CVE-2016-1516 [HIGH] CVE-2016-1516 opencv: Double free vulnerability on crafted image
CVE-2016-1516 opencv: Double free vulnerability on crafted image
OpenCV 3.0.0 has a double free issue that allows attackers to crash OpenCV applications.
Upstream issue:
https://github.com/opencv/opencv/issues/5956
The research paper is noted below.
External reference:
https://arxiv.org/pdf/1701.04739.pdf
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Bugzilla
CVE-2016-1517 opencv: Remote DoS via vectors involving corrupt chunks
bugzilla·2017-04-19·CVSS 5.5
CVE-2016-1517 [MEDIUM] CVE-2016-1517 opencv: Remote DoS via vectors involving corrupt chunks
CVE-2016-1517 opencv: Remote DoS via vectors involving corrupt chunks
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
Upstream issue:
https://github.com/opencv/opencv/issues/5956
The research paper is noted below.
External reference:
https://arxiv.org/pdf/1701.04739.pdf
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Bugzilla
CVE-2016-1701 chromium-browser: use-after-free in autofill
bugzilla·2016-06-02·CVSS 8.8
CVE-2016-1701 [HIGH] CVE-2016-1701 chromium-browser: use-after-free in autofill
CVE-2016-1701 chromium-browser: use-after-free in autofill
An use-after-free flaw was found in the Autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=608101
External References:
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1201 https://access.redhat.com/errata/RHSA-2016:1201
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3594http://www.securitytracker.com/id/1036026https://access.redhat.com/errata/RHSA-2016:1201https://codereview.chromium.org/1960023002https://crbug.com/608101http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3594http://www.securitytracker.com/id/1036026https://access.redhat.com/errata/RHSA-2016:1201https://codereview.chromium.org/1960023002https://crbug.com/608101
2016-06-05
Published