CVE Database
/

CVE-2016-1652

Back to search

CVE-2016-1652

Published: Apr 18, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2016:1136
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2016:1135
vendor-advisory
x_refsource_SUSE
RHSA-2016:0638
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2016:1060
vendor-advisory
x_refsource_SUSE
DSA-3549
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2016:1061
vendor-advisory
x_refsource_SUSE
https://crbug.com/590275
x_refsource_CONFIRM
GLSA-201605-02
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now