CVE-2016-5204

Name
CVE-2016-5204
Description
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
chrome-cve-admin@google.com http://rhn.redhat.com/errata/RHSA-2016-2919.html
chrome-cve-admin@google.com http://www.securityfocus.com/bid/94633
chrome-cve-admin@google.com https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html
chrome-cve-admin@google.com https://crbug.com/630870
chrome-cve-admin@google.com https://security.gentoo.org/glsa/201612-11

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* chrome >= None <= 54.0.2840.99

Vulnerable and fixed packages

Source package Branch Version Maintainer Status