Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-27 CVE-2017-5069 Cross-site Scripting vulnerability in multiple products
Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page.
network
low complexity
google redhat CWE-79
6.1
2017-10-27 CVE-2017-5067 Improper Input Validation vulnerability in multiple products
An insufficient watchdog timer in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google redhat CWE-20
6.5
2017-10-27 CVE-2017-5066 Improper Verification of Cryptographic Signature vulnerability in multiple products
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certificate via a crafted HTML page.
network
low complexity
google redhat CWE-347
6.5
2017-10-27 CVE-2017-5065 Improper Input Validation vulnerability in multiple products
Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Windows and Mac allowed a remote attacker to potentially confuse a user into making an incorrect security decision via a crafted HTML page.
network
low complexity
google redhat CWE-20
4.7
2017-10-27 CVE-2017-5061 Race Condition vulnerability in multiple products
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
high complexity
google redhat CWE-362
5.3
2017-10-27 CVE-2017-5060 Incorrect Authorization vulnerability in multiple products
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
network
low complexity
google redhat CWE-863
6.5
2017-10-26 CVE-2017-1521 Cross-site Scripting vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 and 9.5) is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-10-26 CVE-2017-1232 Cleartext Transmission of Sensitive Information vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
network
high complexity
ibm CWE-319
5.9
2017-10-26 CVE-2017-1230 Information Exposure vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
network
low complexity
ibm CWE-200
5.3
2017-10-26 CVE-2017-1226 Information Exposure vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) generates an error message in error logs that includes sensitive information about its environment which could be used in further attacks against the system.
network
low complexity
ibm CWE-200
4.3