CVE-2016-5143
published 2016-08-07CVE-2016-5143: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase…
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.76%
75.8th percentile
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5144.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 52.0.2743.82 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9mg3-5jw3-fgp2: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-5143 [CRITICAL] GHSA-9mg3-5jw3-fgp2: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5144.
GHSA
GHSA-w2gg-cp64-r9xq: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-5144 [CRITICAL] CWE-284 GHSA-w2gg-cp64-r9xq: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5143.
OSV
oxide-qt vulnerabilities
osv·2016-09-14·CVSS 7.5
CVE-2016-5141 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An issue was discovered in Blink involving the provisional URL for an
initially empty document. An attacker could potentially exploit this to
spoof the currently displayed URL. (CVE-2016-5141)
A use-after-free was discovered in the WebCrypto implementation in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-5142)
It was discovered that the devtools subsystem in Blink mishandles various
parameters. An attacker could exploit this to bypass intended access
restrictions. (CVE-2016-5143, CVE-2016-5144)
It was discovered that Blink does not ensure that a taint property is
preserved after a structure-clone operatio
OSV
CVE-2016-5143: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
osv·2016-08-07·CVSS 9.8
CVE-2016-5143 [CRITICAL] CVE-2016-5143: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5144.
OSV
CVE-2016-5144: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
osv·2016-08-07·CVSS 9.8
CVE-2016-5144 [CRITICAL] CVE-2016-5144: The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5143.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-09-14·CVSS 7.5
CVE-2016-5141 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An issue was discovered in Blink involving the provisional URL for an
initially empty document. An attacker could potentially exploit this to
spoof the currently displayed URL. (CVE-2016-5141)
A use-after-free was discovered in the WebCrypto implementation in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-5142)
It was discovered that the devtools subsystem in Blink mishandles various
parameters. An attacker could exploit this to bypass intended access
restrictions. (CVE-2016-5143, CVE-2016-5144)
It was discovered that Blink does not ensure that a t
Red Hat
chromium-browser: Parameter sanitization failure in DevTools
vendor_redhat·2016-08-03·CVSS 9.8
CVE-2016-5143 [CRITICAL] chromium-browser: Parameter sanitization failure in DevTools
chromium-browser: Parameter sanitization failure in DevTools
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5144.
Red Hat
chromium-browser: Parameter sanitization failure in DevTools
vendor_redhat·2016-08-03·CVSS 9.8
CVE-2016-5144 [CRITICAL] chromium-browser: Parameter sanitization failure in DevTools
chromium-browser: Parameter sanitization failure in DevTools
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5143.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1580.htmlhttp://www.debian.org/security/2016/dsa-3645http://www.securityfocus.com/bid/92276http://www.securitytracker.com/id/1036547https://codereview.chromium.org/2065823004https://crbug.com/619414https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KMX62M7UNRLWO4FEQ6YIMPMTKXXJV6A/https://security.gentoo.org/glsa/201610-09http://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1580.htmlhttp://www.debian.org/security/2016/dsa-3645http://www.securityfocus.com/bid/92276http://www.securitytracker.com/id/1036547https://codereview.chromium.org/2065823004https://crbug.com/619414https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KMX62M7UNRLWO4FEQ6YIMPMTKXXJV6A/https://security.gentoo.org/glsa/201610-09
2016-08-07
Published