2023-11-07 21:03:21 +00:00

142 lines
4.5 KiB
JSON

{
"id": "CVE-2016-1632",
"sourceIdentifier": "chrome-cve-admin@google.com",
"published": "2016-03-06T02:59:03.387",
"lastModified": "2023-11-07T02:30:13.620",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h."
},
{
"lang": "es",
"value": "El subsistema Extensions en Google Chrome en versiones anteriores a 49.0.2623.75 no mantiene adecuadamente sus propias propiedades, lo que permite a atacantes remotos eludir las restricciones destinadas al acceso a trav\u00e9s de c\u00f3digo JavaScript manipulado que desencadena una proyecci\u00f3n incorrecta, relacionada con extensions/renderer/v8_helpers.h y gin/converter.h."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"versionEndIncluding": "48.0.2564.116",
"matchCriteriaId": "99CABF0F-D201-46AE-83DC-09257264BF7D"
}
]
}
]
}
],
"references": [
{
"url": "http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.debian.org/security/2016/dsa-3507",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.securityfocus.com/bid/84008",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.securitytracker.com/id/1035185",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://code.google.com/p/chromium/issues/detail?id=549986",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://codereview.chromium.org/1433293004",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://security.gentoo.org/glsa/201603-09",
"source": "chrome-cve-admin@google.com"
}
]
}