CVE-2017-5095
- EPSS 1.59%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
CVE-2017-5097
- EPSS 1.1%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-5098
- EPSS 3.37%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-5099
- EPSS 1.27%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.
CVE-2017-5100
- EPSS 1.1%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-5101
- EPSS 1.16%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
CVE-2017-5102
- EPSS 1.16%
- Veröffentlicht 27.10.2017 05:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2017-15906
- EPSS 2.66%
- Veröffentlicht 26.10.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
CVE-2017-15873
- EPSS 0.14%
- Veröffentlicht 24.10.2017 20:29:00
- Zuletzt bearbeitet 09.06.2025 16:15:26
The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.
CVE-2017-12613
- EPSS 0.25%
- Veröffentlicht 24.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially r...