Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5075

Опубликовано: 05 июн. 2017
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1459027chromium-browser: information leak in csp reporting

EPSS

Процентиль: 71%
0.00667
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 8 лет назад

Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.

CVSS3: 4.3
nvd
больше 8 лет назад

Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.

CVSS3: 4.3
debian
больше 8 лет назад

Inappropriate implementation in CSP reporting in Blink in Google Chrom ...

CVSS3: 4.3
github
больше 3 лет назад

Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.

CVSS3: 4.3
fstec
больше 8 лет назад

Уязвимость модуля отображения Blink браузера Google Chrome, позволяющая нарушителю получить значения фрагментов URL

EPSS

Процентиль: 71%
0.00667
Низкий

6.5 Medium

CVSS3