CVE-2016-5154 describes multiple heap-based buffer overflows in PDFium, a PDF rendering engine used by Google Chrome and other products like openSUSE. This vulnerability allows remote attackers to trigger a denial of service or potentially achieve arbitrary code execution by crafting a malicious JBig2 image. With a CVSS score of 8.8 (High), it is easily exploitable via user interaction (e.g., opening a malicious PDF) and can lead to high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and it's not on the KEV catalog, there has been some community discussion and media coverage, indicating awareness of this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.