CVE-2016-5172

The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-09-25 20:59

Updated : 2024-02-04 18:53


NVD link : CVE-2016-5172

Mitre link : CVE-2016-5172

CVE.ORG link : CVE-2016-5172


JSON object : View

Products Affected

nodejs

  • node.js

debian

  • debian_linux

google

  • chrome
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor