CVE-2016-1684
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
- Google Chrome
- β€ 50.0.2661.102
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 1.8% (77th percentile)
- NVD status
- Modified
- Published
- 2016-06-05
CVE-2016-1684 at NVD
1 known exploit for CVE-2016-1684
Proof-of-concept code and exploit modules indexed by Sploitus