CVE-2017-5060
- EPSS 0.35%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
CVE-2017-5061
- EPSS 0.26%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2017-5062
- EPSS 0.34%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to potentially perform out of bounds memory access via a crafted Chrome extension.
CVE-2017-5063
- EPSS 0.51%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-5065
- EPSS 0.39%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Windows and Mac allowed a remote attacker to potentially confuse a user into making an incorrect security decision via a crafted HTML page.
CVE-2017-5066
- EPSS 0.13%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certi...
CVE-2017-5067
- EPSS 0.39%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An insufficient watchdog timer in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2017-5068
- EPSS 0.21%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
CVE-2017-5069
- EPSS 0.27%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML p...
CVE-2017-5070
- EPSS 74.38%
- Veröffentlicht 27.10.2017 05:29:00
- Zuletzt bearbeitet 21.04.2026 17:51:00
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.