CVE-2017-15407 — Out-of-bounds Write in Google Chrome
Severity
8.8HIGHNVD
EPSS
1.9%
top 16.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28
Latest updateMay 14
Description
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSA▶
GHSA-69ch-2h2x-j6w3: Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63↗2022-05-14
CVEList▶
CVE-2017-15407: Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63↗2018-08-28
OSV▶
CVE-2017-15407: Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63↗2018-08-28
📋Vendor Advisories
1💬Community
3Bugzilla▶
CVE-2017-15407 CVE-2017-15408 CVE-2017-15409 CVE-2017-15410 CVE-2017-15411 CVE-2017-15412 CVE-2017-15413 CVE-2017-15415 CVE-2017-15416 CVE-2017-15417 CVE-2017-15418 CVE-2017-15419 CVE-2017-15420 CVE-2↗2017-12-07
Bugzilla▶
CVE-2017-15407 CVE-2017-15408 CVE-2017-15409 CVE-2017-15410 CVE-2017-15411 CVE-2017-15412 CVE-2017-15413 CVE-2017-15415 CVE-2017-15416 CVE-2017-15417 CVE-2017-15418 CVE-2017-15419 CVE-2017-15420 CVE-2↗2017-12-07