CVE-2016-1684

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/06/2016
Last modified:
12/04/2025

Description

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 50.0.2661.102 (including)
cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* 1.1.28 (including)


References to Advisories, Solutions, and Tools