CVE-2017-5088 – chromium-browser: out of bounds read in v8
https://notcve.org/view.php?id=CVE-2017-5088
19 Jun 2017 — Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. Una validación insuficiente de entradas no fiables en V8 en Google Chrome, en versiones anteriores a la 59.0.3071.104 para Mac, Windows y Linux y a la 59.0.3071.117 para Android, permitía que un atacante remoto realizase un acceso a la memoria fuera de límites mediante una... • http://www.debian.org/security/2017/dsa-3926 • CWE-125: Out-of-bounds Read •
CVE-2017-5089 – chromium-browser: domain spoofing in omnibox
https://notcve.org/view.php?id=CVE-2017-5089
19 Jun 2017 — Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.104 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name. La falta de mecanismos suficientes para el cumplimiento de políticas en Omnibox en Google Chrome, en versiones anteriores a la 59.0.3071.104 para Mac, permitía que un atacante remoto realizase una suplantación de dominio mediante un nombre de dominio manipulado. • http://www.debian.org/security/2017/dsa-3926 • CWE-20: Improper Input Validation •
CVE-2017-5072 – chromium-browser: address spoofing in omnibox
https://notcve.org/view.php?id=CVE-2017-5072
06 Jun 2017 — Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page. Una implementación inapropiada en Omnibox en Google Chrome, en versiones anteriores a la 59.0.3071.92 para Android, permitía que un atacante remoto realizase una suplantación de dominio con caracteres RTL mediante una página URL manipulada. • http://www.securityfocus.com/bid/98861 • CWE-20: Improper Input Validation •
CVE-2017-5082 – chromium-browser: insufficient hardening in credit card editor
https://notcve.org/view.php?id=CVE-2017-5082
06 Jun 2017 — Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page. Un fallo a la hora de aprovechar las mitigaciones disponibles en el autocompletado de tarjeta de crédito en Google Chrome, en versiones anteriores a la 59.0.3071.92 para Android, permitía que un atacante local realizase capturas de pantalla de linformación de tarjetas de crédito mediante... • http://www.securityfocus.com/bid/98861 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-5076 – chromium-browser: address spoofing in omnibox
https://notcve.org/view.php?id=CVE-2017-5076
06 Jun 2017 — Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. La falta de mecanismos suficientes para el cumplimiento de políticas en Omnibox en Google Chrome en versiones anteriores a la 59.0.3071.86 para Mac, Windows y Linux y a la 59.0.3071.92 para Android, permitía que un atacante remoto realizase una suplantación de dominio medi... • http://www.securityfocus.com/bid/98861 • CWE-20: Improper Input Validation •
CVE-2017-5083 – chromium-browser: ui spoofing in blink
https://notcve.org/view.php?id=CVE-2017-5083
06 Jun 2017 — Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page. Una implementación incorrecta en Blink en Google Chrome, en versiones anteriores a la 59.0.3071.86 para Mac, Windows y Linux y a la 59.0.3071.92 para Android, permitía que un atacante remoto mostrase la interfaz de usuario en una pestaña no controlada por el atacante mediante u... • http://www.securityfocus.com/bid/98861 • CWE-20: Improper Input Validation •
CVE-2017-5078 – chromium-browser: possible command injection in mailto handling
https://notcve.org/view.php?id=CVE-2017-5078
06 Jun 2017 — Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument. Validación insuficiente de entradas no fiables en la manipulación de mailto: de Blink en Google ... • http://www.securityfocus.com/bid/98861 •
CVE-2017-5081 – chromium-browser: extension verification bypass
https://notcve.org/view.php?id=CVE-2017-5081
06 Jun 2017 — Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files. Una falta de verificación de la carpeta locale de una extensión en Google Chrome, en versiones anteriores a la 59.0.3071.86 para Mac, Windows y Linux y a la 59.0.3071.92 para Android, permitía que un atacante con acceso de escritura local modificase extensiones medi... • http://www.securityfocus.com/bid/98861 • CWE-20: Improper Input Validation •
CVE-2017-5075 – chromium-browser: information leak in csp reporting
https://notcve.org/view.php?id=CVE-2017-5075
06 Jun 2017 — Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page. Una implementación inapropiada en la creación de informes de CSP en Blink en Google Chrome, en versiones anteriores a la 59.0.3071.86 para Linux, Windows y Mac y a la 59.0.3071.92 para Android, permitía que un atacante remoto obtuviese el valor de fragmentos de URL media... • http://www.securityfocus.com/bid/98861 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-5071 – chromium-browser: out of bounds read in v8
https://notcve.org/view.php?id=CVE-2017-5071
06 Jun 2017 — Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. Una validación insuficiente de entradas no fiables en V8 en Google Chrome, en versiones anteriores a la 59.0.3071.86 para Linux, Windows y Mac y a la 59.0.3071.92 para Android, permitía que un atacante remoto realizase una lectura de memoria fuera de límites mediante una pági... • http://www.securityfocus.com/bid/98861 • CWE-20: Improper Input Validation •