8.8

CVE-2017-5052

An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers improper casting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version < 57.0.2987.133
   Apple ≫ macOS Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Google ≫ Chrome Version < 57.0.2987.132
   Google ≫ Android Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://security.gentoo.org/glsa/201704-02
http://www.securityfocus.com/bid/97220
https://access.redhat.com/errata/RHSA-2017:0860
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
https://crbug.com/662767