Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-1697
HistoryJun 06, 2016 - 12:00 a.m.

CVE-2016-1697

2016-06-0600:00:00
ubuntu.com
ubuntu.com
12

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.01 Low

EPSS

Percentile

83.8%

The FrameLoader::startLoad function in
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google
Chrome before 51.0.2704.79, does not prevent frame navigations during
DocumentLoader detach operations, which allows remote attackers to bypass
the Same Origin Policy via crafted JavaScript code.

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchchromium-browser< 51.0.2704.79-0ubuntu0.14.04.1.1121UNKNOWN
ubuntu16.04noarchchromium-browser< 51.0.2704.79-0ubuntu0.16.04.1.1242UNKNOWN
ubuntu14.04noarchoxide-qt< 1.15.7-0ubuntu0.14.04.1UNKNOWN
ubuntu15.10noarchoxide-qt< 1.15.7-0ubuntu0.15.10.1UNKNOWN
ubuntu16.04noarchoxide-qt< 1.15.7-0ubuntu0.16.04.1UNKNOWN

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.01 Low

EPSS

Percentile

83.8%