CVE-2016-5172

MEDIUM

Google Chrome < 53.0.2785.101 - Information Disclosure

Title source: rule

Description

The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.

Scores

CVSS v3 6.5
EPSS 0.0113
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (4)

google/chrome < 53.0.2785.101
nodejs/node.js < 6.8.1
debian/debian_linux
debian/debian_linux

Timeline

Published Sep 25, 2016
Tracked Since Feb 18, 2026