8.8

CVE-2016-5198

Warnung
Exploit
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version < 54.0.2840.90
   Linux ≫ Linux Kernel Version -
Google ≫ Chrome Version < 54.0.2840.85
   Google ≫ Android Version -
Google ≫ Chrome Version < 54.0.2840.87
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -

08.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Google Chromium V8 Out-of-Bounds Memory Vulnerability

Schwachstelle

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 34.81% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://rhn.redhat.com/errata/RHSA-2016-2672.html
Third Party Advisory
http://www.securityfocus.com/bid/94079
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1037224
Third Party Advisory
Broken Link
VDB Entry
https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html
Vendor Advisory
Release Notes
https://crbug.com/659475
Exploit
Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-5198
US Government Resource