AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-5166

LOW · CVSS 3.1 EPSS 1.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-09-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-5166
Severity
LOW
CVSS
3.1
EPSS
1.26%
Windows Linux Chrome

Original NVD Description

The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote attackers to discover NetNTLM hashes and conduct SMB relay attacks via a crafted web page that is accessed with the "Save page as" menu choice.