Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Chrome for Mac、Windows和Linux Blink 命令注入漏洞
Vulnerability Description
Google Chrome for Mac、Windows和Linux是美国谷歌(Google)公司开发的一款基于Mac、Windows和Linux平台的Web浏览器。Blink是其中的一个美国谷歌(Google)公司和挪威欧朋(Opera Software)公司共同开发的一套浏览器排版引擎(渲染引擎)。 基于Linux、Windows和Mac平台的Google Chrome 59.0.3071.86之前的版本中的Blink存在命令注入漏洞,该漏洞源于程序没有充分的过滤不可信的输入。远程攻击者可利用该漏洞
CVSS Information
N/A
Vulnerability Type
N/A