8.8
CVE-2016-1676
- EPSS 1.53%
- Veröffentlicht 05.06.2016 23:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Suse ≫ Linux Enterprise Version 12.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.53% | 0.715 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
http://www.debian.org/security/2016/dsa-3590
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.html
http://www.securityfocus.com/bid/90876
http://www.securitytracker.com/id/1035981
https://access.redhat.com/errata/RHSA-2016:1190
https://security.gentoo.org/glsa/201607-07
https://codereview.chromium.org/1903273003
https://crbug.com/604901