CVE-2016-1700 is a use-after-free vulnerability in Google Chrome versions prior to 51.0.2704.79, specifically within the extensions/renderer/runtime_custom_bindings.cc component, affecting various Linux distributions including Debian, OpenSUSE, Red Hat, and SUSE. This flaw arises from the browser's failure to account for side effects when creating an array of extension views. With a CVSS v3 score of 7.5 (HIGH), the vulnerability can be exploited remotely with high attack complexity and user interaction, potentially leading to a denial of service or other unspecified impacts, including high confidentiality, integrity, and availability compromise. While the vulnerability has a low EPSS score and no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered minimal community discussion and media coverage, indicating limited public awareness despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.