Описание
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 60.0.3112.78-0ubuntu1.1363 |
| bionic | released | 60.0.3112.78-0ubuntu1.1363 |
| cosmic | released | 60.0.3112.78-0ubuntu1.1363 |
| devel | released | 60.0.3112.78-0ubuntu1.1363 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [60.0.3112.78-0ubuntu0.14.04.1190]] |
| precise/esm | DNE | |
| trusty | released | 60.0.3112.78-0ubuntu0.14.04.1190 |
| trusty/esm | DNE | trusty was released [60.0.3112.78-0ubuntu0.14.04.1190] |
| upstream | released | 60.0.3112.78 |
| vivid/ubuntu-core | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [Ubuntu touch end-of-life]] |
| esm-infra/xenial | ignored | Ubuntu touch end-of-life |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | trusty was ignored [Ubuntu touch end-of-life] |
| upstream | needs-triage |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
Inappropriate implementation of the web payments API on blob: and data ...
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3