8.8
CVSSv3

CVE-2016-1663

Published: 14/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome prior to 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote malicious users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.1

redhat enterprise linux server supplementary eus 6.7z

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue CVE-2016-1661 Wadih Matar discovered a memory corruption issue CVE-2016-1662 Rob Wu discovered a use-after-free issue related to extensions CVE-2016-1663 A use-after-free issue was discove ...
The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValuecpp in the V8 bindings in Blink, as used in Google Chrome before 500266194, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified othe ...