Description
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code that leverages certain side effects.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3660-1 | chromium-browser security update |
EUVD |
EUVD-2016-6101 | WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code that leverages certain side effects. |
Ubuntu USN |
USN-3058-1 | Oxide vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T00:53:47.912Z
Reserved: 2016-05-31T00:00:00.000Z
Link: CVE-2016-5150
No data.
Status : Deferred
Published: 2016-09-11T10:59:05.380
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-5150
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN