uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published: 2016-06-05T23:00:00

Updated: 2024-08-05T23:02:13.301Z

Reserved: 2016-01-12T00:00:00

Link: CVE-2016-1677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-06-05T23:59:05.927

Modified: 2023-11-07T02:30:33.793

Link: CVE-2016-1677

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-05-25T00:00:00Z

Links: CVE-2016-1677 - Bugzilla