VulnerabilityModified
CVE-2016-5221
Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.
MEDIUM 6.3EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://rhn.redhat.com/errata/RHSA-2016-2919.html
- http://www.securityfocus.com/bid/94633
- https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html
- https://crbug.com/660854
- https://security.gentoo.org/glsa/201612-11
- http://rhn.redhat.com/errata/RHSA-2016-2919.html
- http://www.securityfocus.com/bid/94633
- https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html
- https://crbug.com/660854
- https://security.gentoo.org/glsa/201612-11
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.