6.1
CVSSv3

CVE-2017-15427

Published: 28/08/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Insufficient policy enforcement in Omnibox in Google Chrome before 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

debian debian linux 9.0

Vendor Advisories

Synopsis Critical: chromium-browser security update Type/Severity Security Advisory: Critical Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scor ...
Several vulnerabilities have been discovered in the chromium web browser CVE-2017-15407 Ned Williamson discovered an out-of-bounds write issue CVE-2017-15408 Ke Liu discovered a heap overflow issue in the pdfium library CVE-2017-15409 An out-of-bounds write issue was discovered in the skia library CVE-2017-15410 Luat Nguyen dis ...
Insufficient policy enforcement in Omnibox in Google Chrome prior to 630323984 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar ...
An insufficient blocking of Javascript issue has been found in the Omnibox component of the Chromium browser before 630323984 ...