8.8
CVE-2016-1696
- EPSS 1.24%
- Veröffentlicht 05.06.2016 23:59:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Suse ≫ Linux Enterprise Version 12.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.24% | 0.651 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.html
http://googlechromereleases.blogspot.com/2016/06/stable-channel-update.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.html
http://www.debian.org/security/2016/dsa-3594
http://www.securitytracker.com/id/1036026
https://access.redhat.com/errata/RHSA-2016:1201
https://codereview.chromium.org/1866103002
https://crbug.com/601073