CVE-2016-7395
published 2016-09-11CVE-2016-7395: SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return…
PriorityP430high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.09%
62.0th percentile
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 52.0.2743.116 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89h8-vm89-88m9: SkPath
ghsa_unreviewed·2022-05-17
CVE-2016-7395 [HIGH] GHSA-89h8-vm89-88m9: SkPath
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.
OSV
CVE-2016-7395: SkPath
osv·2016-09-11·CVSS 8.8
CVE-2016-7395 [HIGH] CVE-2016-7395: SkPath
SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2016/dsa-3667http://www.securityfocus.com/bid/92717https://codereview.chromium.org/2006143009https://crbug.com/613918https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.htmlhttp://www.debian.org/security/2016/dsa-3667http://www.securityfocus.com/bid/92717https://codereview.chromium.org/2006143009https://crbug.com/613918https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
2016-09-11
Published