{"api_version":"1","generated_at":"2026-07-23T06:15:38+00:00","cve":"CVE-2016-5204","urls":{"html":"https://cve.report/CVE-2016-5204","api":"https://cve.report/api/cve/CVE-2016-5204.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-5204","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-5204"},"summary":{"title":"CVE-2016-5204","description":"Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.","state":"PUBLISHED","assigner":"Chrome","published_at":"2017-01-19 05:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-79","object corruption"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://security.gentoo.org/glsa/201612-11","name":"https://security.gentoo.org/glsa/201612-11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chromium: Multiple vulnerabilities (GLSA 201612-11) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://crbug.com/630870","name":"https://crbug.com/630870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"630870 - \n Security: Universal XSS by intercepting a UA shadow tree - \n \n chromium -\n \n \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2919.html","name":"http://rhn.redhat.com/errata/RHSA-2016-2919.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html","name":"https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update for Desktop","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94633","name":"http://www.securityfocus.com/bid/94633","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Prior to 55.0.2883.75 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-5204","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5204","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android","version":"affected Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"5204","vulnerable":"1","versionEndIncluding":"54.0.2840.99","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T00:53:48.708Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2016:2919","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2919.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://crbug.com/630870"},{"name":"94633","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/94633"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html"},{"name":"GLSA-201612-11","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201612-11"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android","vendor":"n/a","versions":[{"status":"affected","version":"Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android"}]}],"datePublic":"2016-12-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page."}],"problemTypes":[{"descriptions":[{"description":"object corruption","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-01-04T19:57:01.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"name":"RHSA-2016:2919","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2919.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://crbug.com/630870"},{"name":"94633","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/94633"},{"tags":["x_refsource_CONFIRM"],"url":"https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html"},{"name":"GLSA-201612-11","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201612-11"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2016-5204","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android","version":{"version_data":[{"version_value":"Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"object corruption"}]}]},"references":{"reference_data":[{"name":"RHSA-2016:2919","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2016-2919.html"},{"name":"https://crbug.com/630870","refsource":"CONFIRM","url":"https://crbug.com/630870"},{"name":"94633","refsource":"BID","url":"http://www.securityfocus.com/bid/94633"},{"name":"https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html","refsource":"CONFIRM","url":"https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html"},{"name":"GLSA-201612-11","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201612-11"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2016-5204","datePublished":"2017-01-19T05:43:00.000Z","dateReserved":"2016-05-31T00:00:00.000Z","dateUpdated":"2024-08-06T00:53:48.708Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-01-19 05:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-79","object corruption"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"54.0.2840.99","matchCriteriaId":"85349E1C-5290-4A05-B79B-142BE5B508B5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"5204","Ordinal":"1","Title":"CVE-2016-5204","CVE":"CVE-2016-5204","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"5204","Ordinal":"1","NoteData":"Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.","Type":"Description","Title":"CVE-2016-5204"},{"CveYear":"2016","CveId":"5204","Ordinal":"2","NoteData":"2017-01-19","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"5204","Ordinal":"3","NoteData":"2018-01-04","Type":"Other","Title":"Modified"}]}}}