|
248601
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a c…
|
CWE-416
Use After Free
|
CVE-2017-5056
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248602
|
8.8 |
HIGH
Network
|
google
|
chrome
|
A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
|
CWE-125 CWE-416
Out-of-bounds Read Use After Free
|
CVE-2017-5055
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248603
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5054
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248604
|
9.6 |
CRITICAL
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox vi…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5053
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248605
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exp…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5052
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248606
|
7.5 |
HIGH
Network
|
lenovo
|
thinkcentre_m710s_firmware thinkcentre_m710t_firmware aio_e95_firmware
|
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.
|
NVD-CWE-noinfo
|
CVE-2017-3771
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248607
|
9.8 |
CRITICAL
Network
|
lenovo
|
service_framework
|
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, co…
|
CWE-78
OS Command
|
CVE-2017-3761
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248608
|
8.1 |
HIGH
Network
|
lenovo
|
service_framework
|
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man…
|
CWE-354 CWE-522
Improper Validation of Integrity Check Value Insufficiently Protected Credentials
|
CVE-2017-3760
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248609
|
8.1 |
HIGH
Network
|
lenovo
|
service_framework
|
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote…
|
CWE-20
Improper Input Validation
|
CVE-2017-3759
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248610
|
9.8 |
CRITICAL
Network
|
lenovo
|
service_framework
|
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
|
NVD-CWE-noinfo
|
CVE-2017-3758
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|