Unrated severityNVD Advisory· Published Jan 9, 2019· Updated Aug 6, 2024
CVE-2016-9651
CVE-2016-9651
Description
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweedpkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2012%20SP2
< 55.0.2883.75-3.1+ 1 more
- (no CPE)range: < 55.0.2883.75-3.1
- (no CPE)range: < 55.0.2883.75-2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.exploit-db.com/exploits/42175/mitreexploitx_refsource_EXPLOIT-DB
- rhn.redhat.com/errata/RHSA-2016-2919.htmlmitrevendor-advisoryx_refsource_REDHAT
- security.gentoo.org/glsa/201612-11mitrevendor-advisoryx_refsource_GENTOO
- www.securityfocus.com/bid/94633mitrevdb-entryx_refsource_BID
- chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.htmlmitrex_refsource_CONFIRM
- crbug.com/664411mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.