CVE-2017-5071Improper Input Validation in Google Chrome

Severity
6.3MEDIUMNVD
EPSS
0.7%
top 27.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-wwmg-4r3v-8382: Insufficient validation of untrusted input in V8 in Google Chrome prior to 592022-05-13
OSV
CVE-2017-5071: Insufficient validation of untrusted input in V8 in Google Chrome prior to 592017-10-27

📋Vendor Advisories

1
Red Hat
chromium-browser: out of bounds read in v82017-06-05

💬Community

2
Bugzilla
chromium: various flaws [fedora-all]2017-06-06
Bugzilla
CVE-2017-5071 chromium-browser: out of bounds read in v82017-06-06