CVE-2016-5198 Information
Feb 14, 2021
cve
Description
V8 in Google Chrome prior to 54.0.2840.90 for Linux and 54.0.2840.85 for Android and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions which allowed a remote attacker to perform arbitrary read/write operations leading to code execution via a crafted HTML page.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://rhn.redhat.com/errata/RHSA-2016-2672.html http://www.securityfocus.com/bid/94079 http://www.securitytracker.com/id/1037224 https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html https://crbug.com/659475
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: