AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-5204

MEDIUM · CVSS 6.1 EPSS 1.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-01-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-5204
Severity
MEDIUM
CVSS
6.1
EPSS
1.15%
Windows Linux Android Chrome

Original NVD Description

Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.