CVE-2016-5172
Estado: ModificadaMedia (6.5)—
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.86%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-200
Referencias
- http://rhn.redhat.com/errata/RHSA-2016-1905.html
- http://www.debian.org/security/2016/dsa-3667
- http://www.securityfocus.com/bid/92942
- http://www.securitytracker.com/id/1036826
- https://codereview.chromium.org/2077283004
- https://crbug.com/616386
- https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
- https://security.gentoo.org/glsa/201610-09
- http://rhn.redhat.com/errata/RHSA-2016-1905.html
- http://www.debian.org/security/2016/dsa-3667
- http://www.securityfocus.com/bid/92942
- http://www.securitytracker.com/id/1036826
- https://codereview.chromium.org/2077283004
- https://crbug.com/616386
- https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html
- https://security.gentoo.org/glsa/201610-09
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-5172",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "chrome-cve-admin@google.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-09-25T20:59:04.260",
"references": [
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-1905.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.debian.org/security/2016/dsa-3667",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.securityfocus.com/bid/92942",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://www.securitytracker.com/id/1036826",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://codereview.chromium.org/2077283004",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://crbug.com/616386",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://security.gentoo.org/glsa/201610-09",
"source": "chrome-cve-admin@google.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-1905.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2016/dsa-3667",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/92942",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1036826",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://codereview.chromium.org/2077283004",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://crbug.com/616386",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://googlechromereleases.blogspot.com/2016/09/stable-channel-update-for-desktop_13.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201610-09",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code."
},
{
"lang": "es",
"value": "El analizador en Google V8, como se usa en Google Chrome en versiones anteriores a 53.0.2785.113, no maneja correctamente alcances, lo que permite a atacantes remotos obtener información sensible desde localizaciones de memoria arbitrarias a través de un código JavaScript manipulado."
}
],
"lastModified": "2026-06-17T00:48:54.130",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC271026-1CD7-42F7-8754-1C5144AD590B",
"versionEndIncluding": "53.0.2785.101"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D107EC29-67E7-40C3-8E5A-324C9105C5E4",
"versionEndIncluding": "6.8.1",
"versionStartIncluding": "6.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "chrome-cve-admin@google.com"
}