Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5202

Опубликовано: 25 окт. 2019
Источник: nvd
CVSS3: 9.1
CVSS2: 7.5
EPSS Низкий

Описание

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 54.0.2840.98 (исключая)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 54.0.2840.99 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 54.0.2840.100 (исключая)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00145
Низкий

9.1 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 6 лет назад

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

CVSS3: 8.8
redhat
около 9 лет назад

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

CVSS3: 9.1
debian
больше 6 лет назад

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 5 ...

github
больше 3 лет назад

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

suse-cvrf
около 9 лет назад

Security update for Chromium

EPSS

Процентиль: 35%
0.00145
Низкий

9.1 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-732