Описание
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Not Applicable
- Not Applicable
- Not Applicable
- Not Applicable
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Press/Media Coverage
- Third Party Advisory
- Permissions RequiredVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 17.0.963.78 (исключая)
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
Конфигурация 3Версия до 5.1.7 (исключая)Версия до 5.1.1 (исключая)
Одно из
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.09708
Низкий
10 Critical
CVSS2
Дефекты
CWE-79
Связанные уязвимости
ubuntu
почти 14 лет назад
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
debian
почти 14 лет назад
The extension subsystem in Google Chrome before 17.0.963.78 does not p ...
github
больше 3 лет назад
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
EPSS
Процентиль: 93%
0.09708
Низкий
10 Critical
CVSS2
Дефекты
CWE-79