|
247601
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5112
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247602
|
8.8 |
HIGH
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2017-5111
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247603
|
6.5 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker t…
|
CWE-20
Improper Input Validation
|
CVE-2017-5110
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247604
|
4.3 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attac…
|
CWE-20
Improper Input Validation
|
CVE-2017-5109
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247605
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted PDF file.
|
CWE-843
Type Confusion
|
CVE-2017-5108
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247606
|
5.3 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a cra…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-5107
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247607
|
6.5 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a cra…
|
CWE-20
Improper Input Validation
|
CVE-2017-5106
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247608
|
6.5 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a cra…
|
CWE-20
Improper Input Validation
|
CVE-2017-5105
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247609
|
6.5 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.
|
CWE-20
Improper Input Validation
|
CVE-2017-5104
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247610
|
4.3 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2017-5103
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|