6.5
CVSSv3

CVE-2016-1702

Published: 05/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome prior to 51.0.2704.79, does not validate the interval count, which allows remote malicious users to cause a denial of service (out-of-bounds read) via crafted serialized data.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

redhat enterprise linux desktop 6.0

canonical ubuntu linux 14.04

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

suse linux enterprise 12.0

opensuse leap 42.1

opensuse opensuse 13.2

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2016-1696 A cross-origin bypass was found in the bindings to extensions CVE-2016-1697 Mariusz Mlynski discovered a cross-origin bypass in Blink/Webkit CVE-2016-1698 Rob Wu discovered an information leak CVE-2016-1699 Gregory Panakkal discovered an issu ...
The SkRegion::readFromMemory function in core/SkRegioncpp in Skia, as used in Google Chrome before 510270479, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data ...