Published: 11/09/2016 Updated: 07/01/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SkPath.cpp in Skia, as used in Google Chrome prior to 53.0.2785.89 on Windows and OS X and prior to 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote malicious users to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graphics data.

Affected Products

Vendor Product Versions

Vendor Advisories

Several vulnerabilities have been discovered in the chromium web browser CVE-2016-5170 A use-after-free issue was discovered in Blink/Webkit CVE-2016-5171 Another use-after-free issue was discovered in Blink/Webkit CVE-2016-5172 Choongwoo Han discovered an information leak in the v8 javascript library CVE-2016-5173 A resour ...