← Back

CVE-2016-5202

nvd nist
Published: Oct 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

Affected (3)

Products: Google: Chrome
1 product
Chrome
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 54.0.2840.98
Running on/withPlatform Versions
Apple
Macos
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 54.0.2840.99
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 54.0.2840.100
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (8)

Timeline

No history available yet.