National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2016-1620 Detail

Current Description

Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

Source:  MITRE
View Analysis Description

Impact

CVSS v3.0 Severity and Metrics:

Base Score: 8.8 HIGH
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (V3 legend)
Impact Score: 5.9
Exploitability Score: 2.8


Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope (S): Unchanged
Confidentiality (C): High
Integrity (I): High
Availability (A): High

CVSS v2.0 Severity and Metrics:

Base Score: 9.3 HIGH
Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C) (V2 legend)
Impact Subscore: 10.0
Exploitability Subscore: 8.6


Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (AU): None
Confidentiality (C): Complete
Integrity (I): Complete
Availability (A): Complete
Additional Information:
Victim must voluntarily interact with attack mechanism
Allows unauthorized disclosure of information
Allows unauthorized modification
Allows disruption of service

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00035.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00036.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00046.html
http://rhn.redhat.com/errata/RHSA-2016-0072.html
http://www.debian.org/security/2016/dsa-3456
http://www.securityfocus.com/bid/81430
http://www.securitytracker.com/id/1034801
http://www.ubuntu.com/usn/USN-2877-1
https://code.google.com/p/chromium/issues/detail?id=472618
https://code.google.com/p/chromium/issues/detail?id=514080
https://code.google.com/p/chromium/issues/detail?id=531259
https://code.google.com/p/chromium/issues/detail?id=537656
https://code.google.com/p/chromium/issues/detail?id=539563
https://code.google.com/p/chromium/issues/detail?id=545520
https://code.google.com/p/chromium/issues/detail?id=546814
https://code.google.com/p/chromium/issues/detail?id=549155
https://code.google.com/p/chromium/issues/detail?id=551028
https://code.google.com/p/chromium/issues/detail?id=551143
https://code.google.com/p/chromium/issues/detail?id=552681
https://code.google.com/p/chromium/issues/detail?id=553595
https://code.google.com/p/chromium/issues/detail?id=554129
https://code.google.com/p/chromium/issues/detail?id=554172
https://code.google.com/p/chromium/issues/detail?id=561478
https://code.google.com/p/chromium/issues/detail?id=561488
https://code.google.com/p/chromium/issues/detail?id=561497
https://code.google.com/p/chromium/issues/detail?id=562984
https://code.google.com/p/chromium/issues/detail?id=562986
https://code.google.com/p/chromium/issues/detail?id=565049
https://code.google.com/p/chromium/issues/detail?id=565967
https://code.google.com/p/chromium/issues/detail?id=566231
https://code.google.com/p/chromium/issues/detail?id=569170
https://code.google.com/p/chromium/issues/detail?id=570427
https://code.google.com/p/chromium/issues/detail?id=572406
https://code.google.com/p/chromium/issues/detail?id=576383
https://code.google.com/p/chromium/issues/detail?id=579625
https://security.gentoo.org/glsa/201603-09

Technical Details

Vulnerability Type (View All)

Known Affected Software Configurations Switch to CPE 2.3

Configuration 1 ( hide )
 cpe:/a:google:chrome
     Show Matching CPE(s)
Up to (including)
47.0.2526.106


Change History

6 change records found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2016-1620
NVD Published Date:
01/25/2016
NVD Last Modified:
12/07/2016