[Forgot Password]
Login  Register Subscribe

23631

 
 

115084

 
 

97559

 
 

909

 
 

78730

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-5109

Date: (C)2017-10-30   (M)2017-11-16
 
CVSS Score: 4.3Access Vector: NETWORK
Exploitability Subscore: 8.6Access Complexity: MEDIUM
Impact Subscore: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: PARTIAL
 Availability: NONE











Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.

Reference:
BID-99950
DSA-3926
GLSA-201709-15
https://chromereleases.googleblog.com/2017/07/stable-channel-update-for-desktop.html
https://crbug.com/710400

CPE    3684
cpe:/a:google:chrome:47.0.2526.73
cpe:/a:google:chrome:29.0.1547.13
cpe:/a:google:chrome:13.0.782.19
cpe:/a:google:chrome:29.0.1547.12
...
CWE    1
CWE-20
OVAL    11
oval:org.secpod.oval:def:113068
oval:org.secpod.oval:def:113139
oval:org.secpod.oval:def:41591
oval:org.secpod.oval:def:41592
...

© 2013 SecPod Technologies