Vulnerability · NVD
CVE-2017-15428
CVE-2017-15428, high severity (CVSS 8.8): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 8.8
- Exploitation
- 18.1 %
- Tracked apps
- 2
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
18.12%
moderate exploit risk
percentile 97.0%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Affected <62.0.3202.94 Fixed in 62.0.3202.94 Latest tracked - undetermined
-
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <62.0.3202.94 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <62.0.3202.94 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |