CVE-2017-5030
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium V8 Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 42% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-125
מוצרים מושפעים
google: chrome; apple: macos; linux: linux kernel; microsoft: windows; google: android; debian: debian linux; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation
קישורים
- https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-deskto… Release NotesVendor Advisory
- https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-deskto… Release NotesVendor Advisory
- https://crbug.com/682194 ExploitIssue Tracking
- https://crbug.com/682194 ExploitIssue Tracking
- http://rhn.redhat.com/errata/RHSA-2017-0499.html Third Party Advisory
- http://www.debian.org/security/2017/dsa-3810 Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96767 Broken LinkThird Party AdvisoryVDB Entry
- https://security.gentoo.org/glsa/201704-02 Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-126/ Third Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2017-0499.html Third Party Advisory