CVE-2016-5177

CWE-416Use After Free8 documents7 sources
Severity
8.8HIGH
EPSS
1.9%
top 16.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 14

Description

Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

NVDgoogle/chrome53.0.2785.129
Ubuntuoxide-qt< 1.17.9-0ubuntu0.14.04.1+1
Ubuntuchromium-browser< 53.0.2785.143-0ubuntu0.14.04.1.1142+1
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Fedora 24, 25, Enterprise Linux 6.0

🔴Vulnerability Details

3
GHSA
GHSA-gr2g-c2hj-rpj8: Use-after-free vulnerability in V8 in Google Chrome before 532022-05-14
CVEList
CVE-2016-5177: Use-after-free vulnerability in V8 in Google Chrome before 532017-05-23
OSV
CVE-2016-5177: Use-after-free vulnerability in V8 in Google Chrome before 532016-10-02

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-10-07
Red Hat
chromium-browser: use after free in v82016-09-29

💬Community

2
Bugzilla
CVE-2016-5177 CVE-2016-5178 chromium: various flaws [fedora-all]2016-09-30
Bugzilla
CVE-2016-5177 chromium-browser: use after free in v82016-09-30
CVE-2016-5177 (HIGH CVSS 8.8) | Use-after-free vulnerability in V8 | cvebase.io