CVE-2017-5041Improper Input Validation in Google Chrome

Severity
4.3MEDIUMNVD
OSV8.8
EPSS
0.6%
top 30.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24
Latest updateMay 14

Description

Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a remote attacker to display incorrect information for a site via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDgoogle/chrome57.0.2987.98

🔴Vulnerability Details

3
GHSA
GHSA-c66j-x5g3-3g2m: Google Chrome prior to 572022-05-14
OSV
oxide-qt vulnerabilities2017-03-29
OSV
CVE-2017-5041: Google Chrome prior to 572017-03-10

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2017-03-29
Red Hat
chromium-browser: address spoofing in omnibox2017-03-09

💬Community

2
Bugzilla
chromium: various flaws [fedora-all]2017-03-10
Bugzilla
CVE-2017-5041 chromium-browser: address spoofing in omnibox2017-03-10