CVE-2016-1661
HIGHGoogle Chrome <50.0.2661.94 - Memory Corruption
Title source: llmDescription
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site, related to BindingSecurity.cpp and DOMWindow.cpp.
Exploits (1)
github
NO CODE
31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/Browser/CVE-2016-1661.html
References (12)
Scores
CVSS v3
8.0
EPSS
0.0100
EPSS Percentile
77.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (6)
google/chrome
< 50.0.2661.87
opensuse/opensuse
13.1
redhat/enterprise_linux_desktop_supplementary
6.0
redhat/enterprise_linux_server_supplementary
6.0
redhat/enterprise_linux_server_supplementary_eus
6.7z
redhat/enterprise_linux_workstation_supplementary
6.0
Published
May 14, 2016
Tracked Since
Feb 18, 2026