CVE-2017-5088Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read6 documents5 sources
Severity
8.8HIGHNVD
EPSS
0.9%
top 24.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-r64f-38v8-w4ff: Insufficient validation of untrusted input in V8 in Google Chrome prior to 592022-05-13
OSV
CVE-2017-5088: Insufficient validation of untrusted input in V8 in Google Chrome prior to 592017-10-27

📋Vendor Advisories

1
Red Hat
chromium-browser: out of bounds read in v82017-06-15

💬Community

2
Bugzilla
CVE-2017-5088 chromium-browser: out of bounds read in v82017-06-16
Bugzilla
CVE-2017-5087 CVE-2017-5088 CVE-2017-5089 chromium: various flaws [fedora-all]2017-06-16