Vulnerabilities > Redhat > Enterprise Linux Workstation > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-27 CVE-2017-5118 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google debian redhat CWE-732
4.3
2017-10-27 CVE-2017-5110 Improper Input Validation vulnerability in multiple products
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
network
low complexity
google debian redhat CWE-20
6.5
2017-10-27 CVE-2017-5109 Improper Input Validation vulnerability in multiple products
Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
network
low complexity
google debian redhat CWE-20
4.3
2017-10-27 CVE-2017-5107 Information Exposure Through Discrepancy vulnerability in multiple products
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.
network
high complexity
google redhat CWE-203
5.3
2017-10-27 CVE-2017-5106 Improper Input Validation vulnerability in multiple products
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
network
low complexity
google debian redhat CWE-20
6.5
2017-10-27 CVE-2017-5105 Improper Input Validation vulnerability in multiple products
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
network
low complexity
google debian redhat CWE-20
6.5
2017-10-27 CVE-2017-5104 Improper Input Validation vulnerability in multiple products
Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.
network
low complexity
google debian redhat CWE-20
6.5
2017-10-27 CVE-2017-5103 Use of Uninitialized Resource vulnerability in multiple products
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google debian redhat CWE-908
4.3
2017-10-27 CVE-2017-5102 Use of Uninitialized Resource vulnerability in multiple products
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google debian redhat CWE-908
4.3
2017-10-27 CVE-2017-5101 Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
network
low complexity
google debian redhat
6.5