Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5157

28
FAUCET Score

CVE-2016-5157 is a high-severity heap-based buffer overflow in OpenJPEG's opj_dwt_interleave_v function, impacting Google Chrome on Windows, OS X, and Linux, as well as various Fedora and openSUSE distributions. This vulnerability allows remote attackers to execute arbitrary code by supplying crafted JPEG 2000 data. With a CVSS score of 8.8, it presents a high risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog or having public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
42.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
<= 52.0.2743.116CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
23CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
24CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
25CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.8HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.70%
Probability of exploitation in next 30 days
EPSS Percentile
90.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0470 is in the 91st percentile among its peer group of 14,852 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: chromium-browser-0:53.0.2785.89-3.el6
View patch

Vendor Advisories (1)

redhatCVE-2016-5157Important

chromium-browser: heap overflow in pdfium

Aug 31, 2016

References

lists.opensuse.org / opensuse-security-announce/2016-09/msg00003.html
lists.opensuse.org / opensuse-security-announce/2016-09/msg00004.html
lists.opensuse.org / opensuse-security-announce/2016-09/msg00008.html
lists.opensuse.org / opensuse-updates/2016-09/msg00073.html
rhn.redhat.com / errata/RHSA-2016-1854.html
bugzilla.redhat.com / show_bug.cgi
crbug.com / 632622
github.com / uclouvain/openjpeg/commit/e078172b1c3f98d2219c37076b238fb759c751ea
googlechromereleases.blogspot.com / 2016/08/stable-channel-update-for-desktop_31.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2T6IQAMS4W65MGP7UW5FPE22PXELTK5D
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/66BWMMMWXH32J5AOGLAJGZA3GH5LZHXH
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AQ2IIIQSJ3J4MONBOGCG6XHLKKJX2HKM
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/H4IRSGYMBSHCBZP23CUDIRJ3LBKH6ZJ7
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JYLOX7PZS3ZUHQ6RGI3M6H27B7I5ZZ26
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YGKSEWWWED77Q5ZHK4OA2EKSJXLRU3MK
pdfium.googlesource.com / pdfium/+/b6befb2ed2485a3805cddea86dc7574510178ea9
security.gentoo.org / glsa/201610-09
debian.org / security/2016/dsa-3660
debian.org / security/2017/dsa-4013
openwall.com / lists/oss-security/2016/09/08/5
securityfocus.com / bid/92717
securitytracker.com / id/1036729