4.3
CVSSv2

CVE-2016-1617

Published: 25/01/2016 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome prior to 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote malicious users to determine whether a specific HSTS web site has been visited by reading a CSP report.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities were discovered in the chromium web browser CVE-2015-6792 An issue was found in the handling of MIDI files CVE-2016-1612 cloudfuzzer discovered a logic error related to receiver compatibility in the v8 javascript library CVE-2016-1613 A use-after-free issue was discovered in the pdfium library CVE-2016-1 ...
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSourcecpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 480256482, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a speci ...

Github Repositories

hi i like pyramids

help Tor users circumvent censorship <iframe src="snowflaketorprojectorg/embedhtml" width="320" height="240" frameborder="0" scrolling="no"></iframe> more info $ whoami hacker / ex-physicist $ ls music tweetings max for live device for stemming any audio macOS/win64 vst3 for stemming audi