VDB

CVE-2017-5066

CVE-2017-5066 PUBLISHED CVSS 6.5 MEDIUM

Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certificate via a crafted HTML page.

EPSS 0.73% · 52.5th percentile

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.73%
52.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt1.12.6-0ubuntu1, 1.12.7-0ubuntu1, 1.14.7-0ubuntu1
Ubuntu:16.04:LTSchromium-browser52.0.2743.116-0ubuntu0.16.04.1.1250, 45.0.2454.101-0ubuntu1.1201, 47.0.2526.106-0ubuntu1.1221
Ubuntu:14.04:LTSchromium-browser*, 0, 29.0.1547.65-0ubuntu2

Timeline

  • Apr 20, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 28, 2021 EPSS Score
  • Dec 30, 2021 EPSS Score
  • Mar 3, 2022 EPSS Score
  • May 5, 2022 EPSS Score
  • Jul 7, 2022 EPSS Score
  • Nov 12, 2022 EPSS Score
  • Jan 14, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›