CVE-2017-15429Cross-site Scripting in Google Chrome

Severity
6.1MEDIUMNVD
EPSS
0.7%
top 27.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28
Latest updateMay 14

Description

Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-cqrg-9hh6-w946: Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 632022-05-14
OSV
CVE-2017-15429: Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 632018-08-28

📋Vendor Advisories

1
Red Hat
chromium-browser: uxss in v82017-12-14

💬Community

4
Bugzilla
qt5-qtwebengine: 16 security vulnerabilities2018-03-24
Bugzilla
CVE-2017-15429 chromium: chromium-browser: uxss in v8 [epel-7]2017-12-15
Bugzilla
CVE-2017-15429 chromium-browser: uxss in v82017-12-15
Bugzilla
CVE-2017-15429 chromium: chromium-browser: uxss in v8 [fedora-all]2017-12-15
CVE-2017-15429 — Cross-site Scripting in Google Chrome | cvebase