Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15403

Опубликовано: 09 янв. 2019
Источник: nvd
CVSS3: 7.3
CVSS2: 4.4
EPSS Низкий

Описание

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 61.0.3163.113 (исключая)
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00094
Низкий

7.3 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 7 лет назад

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

CVSS3: 7.3
github
больше 3 лет назад

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

EPSS

Процентиль: 26%
0.00094
Низкий

7.3 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-77