CVE-2016-5131 is a use-after-free vulnerability in libxml2, affecting various products including Google Chrome before version 52.0.2743.82. This flaw, related to the XPointer range-to function, carries a high CVSS score of 8.8, indicating it can be exploited remotely with low complexity, potentially leading to denial of service or other significant impacts like data compromise or system integrity loss. While not listed in CISA's KEV catalog, its FAUCET Risk Score of 75/100 and notable media coverage suggest a recognized threat, despite no public exploit code or Metasploit/Nuclei modules being available. Community discussion around this CVE is also relatively low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52.0.2743.82CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
<= 2.9.4CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | ||
< 10.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.12CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 10.0CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.