MEDIUM · 6.5

CVE-2016-1665

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sens...

Vulnerability Description

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OpensuseOpensuse13.1
RedhatEnterprise Linux Desktop Supplementary6.0
RedhatEnterprise Linux Server Supplementary6.0
RedhatEnterprise Linux Server Supplementary Eus6.7z
RedhatEnterprise Linux Workstation Supplementary6.0
GoogleChrome<= 50.0.2661.87

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1665?

CVE-2016-1665 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sens...

How severe is CVE-2016-1665?

CVE-2016-1665 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-1665?

Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Opensuse, Redhat Enterprise Linux Desktop Supplementary, Redhat Enterprise Linux Server Supplementary, Redhat Enterprise Linux Server Supplementary Eus, Redhat Enterprise Linux Workstation Supplementary.