CVE-2017-5065Improper Input Validation in Google Chrome

Severity
4.7MEDIUMNVD
EPSS
0.7%
top 28.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Windows and Mac allowed a remote attacker to potentially confuse a user into making an incorrect security decision via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-f2wm-xj9m-2hvj: Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 582022-05-13
OSV
CVE-2017-5065: Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 582017-10-27

📋Vendor Advisories

1
Red Hat
chromium-browser: incorrect ui in blink2017-04-19

💬Community

2
Bugzilla
CVE-2017-5065 chromium-browser: incorrect ui in blink2017-04-20
Bugzilla
CVE-2017-5057 CVE-2017-5058 CVE-2017-5059 CVE-2017-5060 CVE-2017-5061 CVE-2017-5062 CVE-2017-5063 CVE-2017-5064 CVE-2017-5065 CVE-2017-5066 CVE-2017-5067 CVE-2017-5069 chromium: various flaws [fedora-2017-04-20