CVE-2018-17480
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium V8 Out-of-Bounds Write Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 34% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-787
מוצרים מושפעים
google: chrome; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation; debian: debian linux
קישורים
- https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-deskto… Vendor Advisory
- https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-deskto… Vendor Advisory
- https://crbug.com/905940 ExploitIssue Tracking
- https://crbug.com/905940 ExploitIssue Tracking
- http://www.securityfocus.com/bid/106084 Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3803 Third Party Advisory
- https://security.gentoo.org/glsa/201908-18 Third Party Advisory
- https://www.debian.org/security/2018/dsa-4352 Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106084 Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3803 Third Party Advisory