Description
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-514-1 | libxslt security update |
Debian DSA |
DSA-3590-1 | chromium-browser security update |
Debian DSA |
DSA-3605-1 | libxslt security update |
EUVD |
EUVD-2016-2779 | numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document. |
Ubuntu USN |
USN-2992-1 | Oxide vulnerabilities |
Ubuntu USN |
USN-3271-1 | Libxslt vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-05T23:02:13.291Z
Reserved: 2016-01-12T00:00:00.000Z
Link: CVE-2016-1684
No data.
Status : Modified
Published: 2016-06-05T23:59:13.117
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-1684
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN