6.8
CVSSv2

CVE-2016-5199

Published: 19/01/2017 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome before 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android allowed a remote malicious user to potentially exploit heap corruption via a crafted video file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Several security issues were fixed in Oxide ...
An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 540284098 for Mac, and 540284099 for Windows, and 5402840100 for Linux, and 550288384 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted video file ...
FFMPEG MP4 decoder contains an off-by-one error resulting in an allocation of size 0, followed by corrupting an arbitrary number of pointers out of bounds on the heap, where each is pointing to controllable or uninitialized data A remote attacker can potentially use this flaw to exploit heap corruption via a crafted video file ...