4.3
CVSSv2

CVE-2016-1652

Published: 18/04/2016 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome prior to 50.0.2661.75 allows remote malicious users to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

suse linux enterprise 12.0

opensuse leap 42.1

google chrome

Vendor Advisories

Several vulnerabilities have been discovered in the chromium web browser CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library CVE-2016-1652 A cross-site scripting issue was discovered in extension bindings CVE-2016-1653 Choongwoo Han discovered an out-of-bounds write issue in the v8 javascript library ...
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_systemcc in the Extensions subsystem in Google Chrome before 500266175 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)" ...