CVE-2016-5174Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
OSV5.9
EPSS
1.1%
top 21.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25
Latest updateMay 14

Description

browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDgoogle/chrome53.0.2785.101
Ubuntusamba/samba< 2:4.7.6+dfsg~ubuntu-0ubuntu2.27

🔴Vulnerability Details

3
GHSA
GHSA-2jpv-7wj6-667v: browser/ui/cocoa/browser_window_controller_private2022-05-14
OSV
samba regression2021-12-13
OSV
CVE-2016-5174: browser/ui/cocoa/browser_window_controller_private2016-09-25

📋Vendor Advisories

1
Red Hat
chromium-browser: popup not correctly suppressed2016-09-13

💬Community

2
Bugzilla
CVE-2016-5174 chromium-browser: popup not correctly suppressed2016-09-14
Bugzilla
CVE-2016-5170 CVE-2016-5171 CVE-2016-5172 CVE-2016-5173 CVE-2016-5174 CVE-2016-5175 chromium: various flaws [fedora-all]2016-09-14