CVE-2016-5204
published 2017-01-19CVE-2016-5204: Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and…
PriorityP423medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.15%
63.7th percentile
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 54.0.2840.99 | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-12-09·CVSS 6.1
CVE-2016-5204 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple vulnerabilities were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
read uninitialized memory, obtain sensitive information, spoof the
webview URL, bypass same origin restrictions, cause a denial of service
via application crash, or execute arbitrary code. (CVE-2016-5204,
CVE-2016-5205, CVE-2016-5207, CVE-2016-5208, CVE-2016-5209, CVE-2016-5212,
CVE-2016-5215, CVE-2016-5222, CVE-2016-5224, CVE-2016-5225, CVE-2016-5226,
CVE-2016-9650, CVE-2016-9652)
Multiple vulnerabilities were discovered in V8. If a user were tricked in
to opening a specially crafted website, an a
Red Hat
chromium-browser: universal xss in blink
vendor_redhat·2016-12-01·CVSS 6.1
CVE-2016-5204 [MEDIUM] chromium-browser: universal xss in blink
chromium-browser: universal xss in blink
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
VulDB
Google Chrome up to 55 Blink cross site scripting (RHSA-2016:2919 / Nessus ID 95661)
vuldb·2026-05-14·CVSS 6.1
CVE-2016-5204 [MEDIUM] Google Chrome up to 55 Blink cross site scripting (RHSA-2016:2919 / Nessus ID 95661)
A vulnerability classified as critical was found in Google Chrome up to 55. Affected by this vulnerability is an unknown functionality of the component Blink. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2016-5204. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-cxhh-qg68-3rq3: Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55
ghsa_unreviewed·2022-05-14
CVE-2016-5204 [MEDIUM] CWE-79 GHSA-cxhh-qg68-3rq3: Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
OSV
oxide-qt vulnerabilities
osv·2016-12-09·CVSS 6.1
CVE-2016-5204 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple vulnerabilities were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
read uninitialized memory, obtain sensitive information, spoof the
webview URL, bypass same origin restrictions, cause a denial of service
via application crash, or execute arbitrary code. (CVE-2016-5204,
CVE-2016-5205, CVE-2016-5207, CVE-2016-5208, CVE-2016-5209, CVE-2016-5212,
CVE-2016-5215, CVE-2016-5222, CVE-2016-5224, CVE-2016-5225, CVE-2016-5226,
CVE-2016-9650, CVE-2016-9652)
Multiple vulnerabilities were discovered in V8. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit these to obtain sensitive
OSV
CVE-2016-5204: Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55
osv·2016-12-06·CVSS 6.1
CVE-2016-5204 [MEDIUM] CVE-2016-5204: Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print()
hackerone·2019-10-08·CVSS 9.8
CVE-2017-5204 [CRITICAL] CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print()
CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print()
Reported to the project maintainer in October 2016. A specially crafted IPv6 packet could trigger a read outside of buffer in tcpdump.
```
==27882==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x60400000e000 at pc 0x0000005724b5 bp 0x7ffe8e17a790 sp 0x7ffe8e17a788
READ of size 1 at 0x60400000e000 thread T0
#0 0x5724b4 in ip6_print /root/tcpdump/./print-ip6.c:296:4
#1 0x5707d0 in ipN_print /root/tcpdump/./print-ip.c:689:3
#2 0x61cde7 in raw_if_print /root/tcpdump/./print-raw.c:42:2
#3 0x4ddd19 in pretty_print_packet /root/tcpdump/./print.c:339:18
#4 0x4cc5db in print_packet /root/tcpdump/./tcpdump.c:2492:2
#5 0x7672a0 in pcap_offline_read /root/libpcap/./savefile.c:527:4
#6
Bugzilla
chromium: various flaws [fedora-all]
bugzilla·2016-12-02·CVSS 8.8
[HIGH] chromium: various flaws [fedora-all]
chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has b
Bugzilla
CVE-2016-5204 chromium-browser: universal xss in blink
bugzilla·2016-12-02·CVSS 6.1
CVE-2016-5204 [MEDIUM] CVE-2016-5204 chromium-browser: universal xss in blink
CVE-2016-5204 chromium-browser: universal xss in blink
An universal xss flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=630870
External References:
https://googlechromereleases.blogspot.com/2016/12/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1400883]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:2919 https://rhn.redhat.com/errata/RHSA-2016-2919.html
http://rhn.redhat.com/errata/RHSA-2016-2919.htmlhttp://www.securityfocus.com/bid/94633https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/630870https://security.gentoo.org/glsa/201612-11http://rhn.redhat.com/errata/RHSA-2016-2919.htmlhttp://www.securityfocus.com/bid/94633https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/630870https://security.gentoo.org/glsa/201612-11
2017-01-19
Published