|
250721
|
7.8 |
HIGH
Local
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a craf…
|
CWE-416
Use After Free
|
CVE-2017-5039
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250722
|
6.3 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a cra…
|
CWE-416
Use After Free
|
CVE-2017-5038
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250723
|
7.8 |
HIGH
Local
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5037
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250724
|
7.8 |
HIGH
Local
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF f…
|
CWE-416
Use After Free
|
CVE-2017-5036
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250725
|
8.1 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.
|
CWE-362
Race Condition
|
CVE-2017-5035
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250726
|
8.8 |
HIGH
Network
|
google
|
chrome
|
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2017-5034
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250727
|
4.3 |
MEDIUM
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote att…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2017-5033
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250728
|
8.8 |
HIGH
Network
|
google
|
chrome
|
PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF …
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5032
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250729
|
8.8 |
HIGH
Network
|
google
|
chrome
|
A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2017-5031
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250730
|
8.8 |
HIGH
Network
|
google xmlsoft debian redhat
|
chrome libxslt debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for …
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5029
|
2024-11-21 12:26 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|