CVE-2016-9642
published 2017-02-03CVE-2016-9642: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
PriorityP414medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.19%
40.3th percentile
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | safari | — | — |
| apple | tvos | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2017-04-10
CVE-2016-9642 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK+.
A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
Apple
CVE-2016-9642: iOS 10.3
vendor_apple·2017-03-27·CVSS 5.5
CVE-2016-9642 [MEDIUM] CVE-2016-9642: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2016-9642
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved input validation.
Apple
CVE-2016-9642: tvOS 10.2
vendor_apple·2017-03-27·CVSS 5.5
CVE-2016-9642 [MEDIUM] CVE-2016-9642: tvOS 10.2
Apple Security Update: About the security content of tvOS 10.2
Product: tvOS
Version: 10.2
CVE: CVE-2016-9642
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved input validation.
Apple
CVE-2016-9642: Safari 10.1
vendor_apple·2017-03-27·CVSS 5.5
CVE-2016-9642 [MEDIUM] CVE-2016-9642: Safari 10.1
Apple Security Update: About the security content of Safari 10.1
Product: Safari
Version: 10.1
CVE: CVE-2016-9642
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved input validation.
GHSA
GHSA-v9jj-hfg8-mx43: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file
ghsa_unreviewed·2022-05-17
CVE-2016-9642 [MEDIUM] CWE-125 GHSA-v9jj-hfg8-mx43: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
OSV
CVE-2016-9642: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file
osv·2017-02-03·CVSS 5.5
CVE-2016-9642 [MEDIUM] CVE-2016-9642: JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2016/11/26/4http://www.securityfocus.com/bid/94554http://www.securitytracker.com/id/1038137https://security.gentoo.org/glsa/201706-15http://www.openwall.com/lists/oss-security/2016/11/26/4http://www.securityfocus.com/bid/94554http://www.securitytracker.com/id/1038137https://security.gentoo.org/glsa/201706-15
2017-02-03
Published