607
VMScore

CVE-2016-1667

Published: 14/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 607
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome prior to 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote malicious users to bypass the Same Origin Policy via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.1

debian debian linux 8.0

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...