← Back

CVE-2016-1677

nvd nist
Published: Jun 5, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

Affected (12)

Products: Google: Chrome, V8 · Canonical: Ubuntu Linux · Debian: Debian Linux · +3 more
Show all products
2 products
Chrome
V8
1 product
Ubuntu Linux
1 product
Debian Linux
2 products
Leap
Opensuse
3 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
1 product
Linux Enterprise
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 50.0.2661.102
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 15.10
Version 16.04
Version 8.0
Version 42.1
Version 13.2
Version 6.0
Version 6.0
Version 6.0
Version 12.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.1.281

References (24)

Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.