CVE-2017-5010 PUBLISHED

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

EPSS 0.41% · 61.1th percentile

Risk Scores

EPSS Score
0.41%
61.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt1.18.3-0ubuntu0.16.04.1, 1.17.9-0ubuntu0.16.04.1, 1.17.7-0ubuntu0.16.04.1
Ubuntu:16.04:LTSchromium-browser48.0.2564.82-0ubuntu1.1222, 55.0.2883.87-0ubuntu0.16.04.1263, 53.0.2785.143-0ubuntu0.16.04.1.1257
Ubuntu:14.04:LTSoxide-qt1.16.5-0ubuntu0.14.04.1, 1.17.9-0ubuntu0.14.04.1, 1.18.3-0ubuntu0.14.04.1
Ubuntu:14.04:LTSchromium-browser0, 53.0.2785.143-0ubuntu0.14.04.1.1145, 53.0.2785.143-0ubuntu0.14.04.1.1142

Timeline

References

Open in Interactive Console →