Vulnerabilities
Vulnerable Software
Google:  >> Chrome  >> 10.0.648.131  Security Vulnerabilities
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.
CVSS Score
4.3
EPSS Score
0.039
Published
2017-04-24
Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a remote attacker to display incorrect information for a site via a crafted HTML page.
CVSS Score
4.3
EPSS Score
0.006
Published
2017-04-24
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
CVSS Score
5.7
EPSS Score
0.0
Published
2017-04-24
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
CVSS Score
8.8
EPSS Score
0.011
Published
2017-04-24
Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVSS Score
6.3
EPSS Score
0.01
Published
2017-04-24
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.
CVSS Score
6.1
EPSS Score
0.009
Published
2017-04-24
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient policy enforcement, which allowed a remote attacker to spoof the location object via a crafted HTML page, related to Blink information disclosure.
CVSS Score
4.3
EPSS Score
0.012
Published
2017-04-24
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.
CVSS Score
9.8
EPSS Score
0.017
Published
2017-04-24
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
CVSS Score
7.5
EPSS Score
0.096
Published
2017-04-21
Google Chrome caches TLS sessions before certificate validation occurs.
CVSS Score
6.5
EPSS Score
0.0
Published
2017-04-13


Contact Us

Shodan ® - All rights reserved