cbcvebase.
CVE-2016-5202
published 2019-10-25

CVE-2016-5202: browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux…

PriorityP339critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.79%
52.7th percentile
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

Affected

6 ranges
VendorProductVersion rangeFixed in
chromium-browserchromium-browser
chromium-browserchromium-browser>= 0 < 58.0.3029.81-0ubuntu0.14.04.117258.0.3029.81-0ubuntu0.14.04.1172
chromium-browserchromium-browser>= 0 < 55.0.2883.87-0ubuntu0.16.04.126355.0.2883.87-0ubuntu0.16.04.1263
googlechrome< 54.0.2840.9854.0.2840.98
googlechrome< 54.0.2840.9954.0.2840.99
googlechrome< 54.0.2840.10054.0.2840.100

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.