9.3
CVSSv2

CVE-2016-1648

Published: 29/03/2016 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome prior to 49.0.2623.108 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

opensuse opensuse 13.1

debian debian linux 8.0

Vendor Advisories

Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindingscc in the Extensions implementation in Google Chrome before 4902623108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2016-1646 Wen Xu discovered an out-of-bounds read issue in the v8 library CVE-2016-1647 A use-after-free issue was discovered CVE-2016-1648 A use-after-free issue was discovered in the handling of extensions CVE-2016-1649 lokihardt discovered a buffer ...