Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka "Universal XSS (UXSS)."
References
Configurations
History
21 Nov 2024, 02:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00003.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00004.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00008.html - | |
References | () http://lists.opensuse.org/opensuse-updates/2016-09/msg00073.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2016-1854.html - | |
References | () http://www.debian.org/security/2016/dsa-3660 - | |
References | () http://www.securityfocus.com/bid/92717 - | |
References | () http://www.securitytracker.com/id/1036729 - | |
References | () https://codereview.chromium.org/2134113002 - | |
References | () https://crbug.com/621362 - | |
References | () https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html - | |
References | () https://security.gentoo.org/glsa/201610-09 - |
07 Nov 2023, 02:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.debian.org/security/2016/dsa-3660 - | |
References | () https://security.gentoo.org/glsa/201610-09 - | |
References | () http://www.securitytracker.com/id/1036729 - | |
References | () http://rhn.redhat.com/errata/RHSA-2016-1854.html - | |
References | () https://codereview.chromium.org/2134113002 - | |
References | () http://www.securityfocus.com/bid/92717 - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00003.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00004.html - | |
References | () http://lists.opensuse.org/opensuse-updates/2016-09/msg00073.html - | |
References | () https://crbug.com/621362 - | |
References | () https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00008.html - |
Information
Published : 2016-09-11 10:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-5148
Mitre link : CVE-2016-5148
CVE.ORG link : CVE-2016-5148
JSON object : View
Products Affected
- chrome
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')