[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2017-5042Date: (C)2017-04-26   (M)2023-12-22


Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.7CVSS Score : 3.3
Exploit Score: 2.1Exploit Score: 6.5
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: ADJACENT_NETWORKAccess Vector: ADJACENT_NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
-96767
DSA-3810
GLSA-201704-02
RHSA-2017:0499
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
https://crbug.com/671932

CPE    9
cpe:/o:debian:debian_linux:9.0
cpe:/o:linux:linux_kernel:-
cpe:/o:google:android:-
cpe:/o:debian:debian_linux:8.0
...
CWE    1
CWE-311
OVAL    10
oval:org.secpod.oval:def:505256
oval:org.secpod.oval:def:39213
oval:org.secpod.oval:def:39218
oval:org.secpod.oval:def:39274
...

© SecPod Technologies