CVE-2017-5027 PUBLISHED

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

EPSS 0.11% · 29.2th percentile

Risk Scores

EPSS Score
0.11%
29.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSoxide-qt1.10.3-0ubuntu0.14.04.1, 1.2.5-0ubuntu0.14.04.1, 1.3.4-0ubuntu0.14.04.1
Ubuntu:16.04:LTSchromium-browser55.0.2883.87-0ubuntu0.16.04.1263, 53.0.2785.143-0ubuntu0.16.04.1.1257, 53.0.2785.143-0ubuntu0.16.04.1.1254
Ubuntu:16.04:LTSoxide-qt1.19.4-0ubuntu0.16.04.1, 0, 1.9.5-0ubuntu1
Ubuntu:14.04:LTSchromium-browser38.0.2125.111-0ubuntu0.14.04.1.1061, 37.0.2062.120-0ubuntu0.14.04.1~pkg1049, 37.0.2062.94-0ubuntu0.14.04.1~pkg1042

Timeline

References

Open in Interactive Console →