CVE-2016-5146
published 2016-08-07CVE-2016-5146: Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via…
PriorityP335critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.36%
68.9th percentile
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 52.0.2743.82 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqgx-4h63-gcfm: Multiple unspecified vulnerabilities in Google Chrome before 52
ghsa_unreviewed·2022-05-17
CVE-2016-5146 [CRITICAL] GHSA-gqgx-4h63-gcfm: Multiple unspecified vulnerabilities in Google Chrome before 52
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2016-09-14·CVSS 7.5
CVE-2016-5141 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An issue was discovered in Blink involving the provisional URL for an
initially empty document. An attacker could potentially exploit this to
spoof the currently displayed URL. (CVE-2016-5141)
A use-after-free was discovered in the WebCrypto implementation in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-5142)
It was discovered that the devtools subsystem in Blink mishandles various
parameters. An attacker could exploit this to bypass intended access
restrictions. (CVE-2016-5143, CVE-2016-5144)
It was discovered that Blink does not ensure that a taint property is
preserved after a structure-clone operatio
OSV
CVE-2016-5146: Multiple unspecified vulnerabilities in Google Chrome before 52
osv·2016-08-07·CVSS 9.8
CVE-2016-5146 [CRITICAL] CVE-2016-5146: Multiple unspecified vulnerabilities in Google Chrome before 52
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-09-14·CVSS 7.5
CVE-2016-5141 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An issue was discovered in Blink involving the provisional URL for an
initially empty document. An attacker could potentially exploit this to
spoof the currently displayed URL. (CVE-2016-5141)
A use-after-free was discovered in the WebCrypto implementation in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-5142)
It was discovered that the devtools subsystem in Blink mishandles various
parameters. An attacker could exploit this to bypass intended access
restrictions. (CVE-2016-5143, CVE-2016-5144)
It was discovered that Blink does not ensure that a t
Red Hat
chromium-browser: various fixes from internal audits
vendor_redhat·2016-08-03·CVSS 9.8
CVE-2016-5146 [CRITICAL] chromium-browser: various fixes from internal audits
chromium-browser: various fixes from internal audits
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1580.htmlhttp://www.debian.org/security/2016/dsa-3645http://www.securityfocus.com/bid/92276http://www.securitytracker.com/id/1036547https://crbug.com/620277https://crbug.com/620766https://crbug.com/633310https://crbug.com/633486https://security.gentoo.org/glsa/201610-09http://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1580.htmlhttp://www.debian.org/security/2016/dsa-3645http://www.securityfocus.com/bid/92276http://www.securitytracker.com/id/1036547https://crbug.com/620277https://crbug.com/620766https://crbug.com/633310https://crbug.com/633486https://security.gentoo.org/glsa/201610-09
2016-08-07
Published