CVE-2017-0860
published 2017-11-16CVE-2017-0860: An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2…
PriorityP423medium5.3CVSS 3.0
AVLACLPRLUINSUCLILAL
EPSS
0.13%
2.9th percentile
An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-31097064.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5056 chromium-browser: use after free in blink
bugzilla·2017-03-30·CVSS 8.8
CVE-2017-5056 [HIGH] CVE-2017-5056 chromium-browser: use after free in blink
CVE-2017-5056 chromium-browser: use after free in blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=705445
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1437355]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0860 https://access.redhat.com/errata/RHSA-2017:0860
Bugzilla
CVE-2017-5052 chromium-browser: bad cast in blink
bugzilla·2017-03-30·CVSS 8.8
CVE-2017-5052 [HIGH] CVE-2017-5052 chromium-browser: bad cast in blink
CVE-2017-5052 chromium-browser: bad cast in blink
A bad cast flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=662767
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1437355]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0860 https://access.redhat.com/errata/RHSA-2017:0860
Bugzilla
CVE-2017-5054 chromium-browser: heap buffer overflow in v8
bugzilla·2017-03-30·CVSS 8.8
CVE-2017-5054 [HIGH] CVE-2017-5054 chromium-browser: heap buffer overflow in v8
CVE-2017-5054 chromium-browser: heap buffer overflow in v8
A heap buffer overflow flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=699166
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1437355]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0860 https://access.redhat.com/errata/RHSA-2017:0860
Bugzilla
CVE-2017-5053 chromium-browser: out of bounds memory access in v8
bugzilla·2017-03-30·CVSS 9.6
CVE-2017-5053 [CRITICAL] CVE-2017-5053 chromium-browser: out of bounds memory access in v8
CVE-2017-5053 chromium-browser: out of bounds memory access in v8
An out of bounds memory access flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=702058
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1437355]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0860 https://access.redhat.com/errata/RHSA-2017:0860
Bugzilla
CVE-2017-5055 chromium-browser: use after free in printing
bugzilla·2017-03-30·CVSS 8.8
CVE-2017-5055 [HIGH] CVE-2017-5055 chromium-browser: use after free in printing
CVE-2017-5055 chromium-browser: use after free in printing
An use after free flaw was found in the printing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=698622
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1437355]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0860 https://access.redhat.com/errata/RHSA-2017:0860
2017-11-16
Published