CVE-2016-5198
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium V8 Out-of-Bounds Memory Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 35% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-787
מוצרים מושפעים
google: chrome; linux: linux kernel; google: android; apple: macos; microsoft: windows; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation
קישורים
- https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-deskto… Release NotesVendor Advisory
- https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-deskto… Release NotesVendor Advisory
- https://crbug.com/659475 ExploitIssue Tracking
- https://crbug.com/659475 ExploitIssue Tracking
- http://rhn.redhat.com/errata/RHSA-2016-2672.html Third Party Advisory
- http://www.securityfocus.com/bid/94079 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037224 Broken LinkThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-2672.html Third Party Advisory
- http://www.securityfocus.com/bid/94079 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037224 Broken LinkThird Party AdvisoryVDB Entry