4.3
CVSSv3

CVE-2017-5118

Published: 27/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Blink in Google Chrome before 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote malicious user to bypass content security policy via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 9.0

debian debian linux 10.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

Vendor Advisories

Several vulnerabilities have been discovered in the chromium web browser CVE-2017-5111 Luat Nguyen discovered a use-after-free issue in the pdfium library CVE-2017-5112 Tobias Klein discovered a buffer overflow issue in the webgl library CVE-2017-5113 A buffer overflow issue was discovered in the skia library CVE-2017-5114 ...
Blink in Google Chrome prior to 610316379 for Mac, Windows, and Linux, and 610316381 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page ...
A content security policy bypass vulnerability has been found in the Blink component of the Chromium browser < 610316379 ...