CVE-2016-5172

EUVD-2016-6123
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 53.0.2785.101
nodejsnode.js
6.0.0 ≤
𝑥
≤ 6.8.1
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
precise
ignored
trusty
Fixed 53.0.2785.143-0ubuntu0.14.04.1.1142
released
xenial
Fixed 53.0.2785.143-0ubuntu0.16.04.1.1254
released
yakkety
Fixed 53.0.2785.143-0ubuntu1.1307
released
oxide-qt
precise
dne
trusty
Fixed 1.17.9-0ubuntu0.14.04.1
released
xenial
Fixed 1.17.9-0ubuntu0.16.04.1
released
yakkety
Fixed 1.17.9-0ubuntu1
released