Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5018

Опубликовано: 25 янв. 2017
Источник: redhat
CVSS3: 6.5

Описание

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1416670chromium-browser: universal xss in chrome://apps

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

CVSS3: 6.1
nvd
больше 9 лет назад

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

CVSS3: 6.1
debian
больше 9 лет назад

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56 ...

CVSS3: 6.1
github
больше 4 лет назад

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

suse-cvrf
больше 9 лет назад

Security update of chromium

6.5 Medium

CVSS3