CVE-2016-5204

Source
https://cve.org/CVERecord?id=CVE-2016-5204
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5204.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-5204
Downstream
Related
Published
2017-01-19T05:59:00.387Z
Modified
2026-03-15T14:20:26.024182Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "54.0.2840.99"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5204.json"