V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-5016
DEB
Medium

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI element…

CVSS
6.5
Medium
EPSS
0.01
p66
Published
2017-01-01
Updated
2017-01-01
Description

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

Tags · CWE
Pre-auth
CWE-1021
CAPEC-103
CAPEC-181
CAPEC-222
CAPEC-504
CAPEC-506
CAPEC-587
CAPEC-654
Affected products
Chrome ≤ 55.0.2883.87
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.013 · p66
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-504 · CWE-1021
└ via CAPEC-654 · CWE-1021
└ via CAPEC-654 · CWE-1021
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
oxide-qtTracked
oxide-qtTracked
oxide-qtTracked
oxide-qtTracked
chrome*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities