← All CVEs

CVE-2017-5116

high · 8.8

Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

8.8
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2017-10-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-843

Affected products

VendorProductAffected versions
googlechrome< 61.0.3163.79
applemacosall versions
linuxlinux_kernelall versions
microsoftwindowsall versions
googlechrome< 61.0.3163.81
googleandroidall versions
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_workstation6.0
debiandebian_linux9.0
debiandebian_linux10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-5116