CVE-2016-5168
published 2017-04-21CVE-2016-5168: Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.73%
75.3th percentile
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 50.0.2661.91 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9q7-484c-gjr6: Skia, as used in Google Chrome before 50
ghsa_unreviewed·2022-05-17
CVE-2016-5168 [HIGH] CWE-346 GHSA-q9q7-484c-gjr6: Skia, as used in Google Chrome before 50
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
OSV
CVE-2016-5168: Skia, as used in Google Chrome before 50
osv·2017-04-21·CVSS 7.5
CVE-2016-5168 [HIGH] CVE-2016-5168: Skia, as used in Google Chrome before 50
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/89106https://bugs.chromium.org/p/chromium/issues/detail?id=586820https://chromereleases.googleblog.com/2016/04/stable-channel-update_28.htmlhttps://www.contextis.com//documents/2/Browser_Timing_Attacks.pdfhttp://www.securityfocus.com/bid/89106https://bugs.chromium.org/p/chromium/issues/detail?id=586820https://chromereleases.googleblog.com/2016/04/stable-channel-update_28.htmlhttps://www.contextis.com//documents/2/Browser_Timing_Attacks.pdf
2017-04-21
Published