Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-5081


Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.


Published

2017-10-27T05:29:01.237

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google chrome < 59.0.3071.86 Yes
Operating System apple macos - No
Operating System linux linux_kernel - No
Operating System microsoft windows - No
Operating System debian debian_linux 9.0 Yes
Application google chrome < 59.0.3071.92 Yes
Operating System google android - No
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes

References