CVE-2016-1683 is a high-severity vulnerability in libxslt versions prior to 1.1.29, notably affecting Google Chrome before 51.0.2704.63, as well as various Linux distributions. It stems from improper handling of namespace nodes, allowing remote attackers to trigger a denial of service via out-of-bounds heap memory access with a crafted document, potentially leading to further unspecified impacts. The attack requires user interaction (e.g., opening a malicious document) and has high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it was mentioned in a SecurityWeek article regarding Chrome 51 patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.28CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.