9.3
CVSSv2

CVE-2016-1643

Published: 13/03/2016 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome prior to 49.0.2623.87, does not properly maintain the user agent shadow DOM, which allows remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2016-1643 cloudfuzzer discovered a type confusion issue in Blink/Webkit CVE-2016-1644 Atte Kettunen discovered a use-after-free issue in Blink/Webkit CVE-2016-1645 An out-of-bounds write issue was discovered in the pdfium library For the stable distributi ...