Lucene search

K
nessusTenable700054.PASL
HistoryApr 10, 2017 - 12:00 a.m.

Google Chrome < 57.0.2987.133 Multiple Vulnerabilities

2017-04-1000:00:00
Tenable
www.tenable.com
19

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.016

Percentile

87.2%

The version of Google Chrome installed on the remote host is prior to 57.0.2987.133, and is affected by multiple vulnerabilities :

  • A bad cast flaw exists in the β€˜LayoutInline::absoluteVisualRect()’ function in β€˜layout/LayoutInline.cpp’ that may allow a context-dependent attacker to have an unspecified impact. (CVE-2017-5052)
  • A use-after-free error exists in the β€˜PrintViewManager’ class in printing’/print_view_manager.cc’ that is triggered when handling previews. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. (CVE-2017-5055)
  • A use-after-free error exists in β€˜Blink’ that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. (CVE-2017-5056)
Binary data 700054.pasl

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.016

Percentile

87.2%