Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-5105

Quick assessment

Affected
n/a Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Google Chrome for Linux、Windows、Mac和Android是美国谷歌(Google)公司开发的一款基于Linux、Windows、Mac和Android平台的Web浏览器。Omnibox是其中的一个实时搜索引擎。 基于Mac, Windows, Linux和Android平台的Google Chrome 60.0.3112.78之前的版本中的Omnibox存在安全漏洞,该漏洞源于程序没有充分的强制执行策略。远程攻击者可借助特制域名中IDN的同形异义词利用该漏洞伪造域名。

AI Predicted 5.9 Difficulty: Trivial EPSS 1.34% · P69
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-5105

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Google Chrome for Linux、Windows、Mac和Android Omnibox 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Chrome for Linux、Windows、Mac和Android是美国谷歌(Google)公司开发的一款基于Linux、Windows、Mac和Android平台的Web浏览器。Omnibox是其中的一个实时搜索引擎。 基于Mac, Windows, Linux和Android平台的Google Chrome 60.0.3112.78之前的版本中的Omnibox存在安全漏洞,该漏洞源于程序没有充分的强制执行策略。远程攻击者可借助特制域名中IDN的同形异义词利用该漏洞伪造域名。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux and Android -

II. Public POCs for CVE-2017-5105

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-5105

登录查看更多情报信息。

Vendor Advisories for CVE-2017-5105 (5)

Other References for CVE-2017-5105 (1)

Same Patch Batch · n/a · 2017-10-27 · 91 CVEs total

CVE-2017-5090 Google Chrome for Mac Omnibox 安全漏洞
CVE-2017-5087 Google Chrome for Linux、Windows、Mac和Android Blink 安全漏洞
CVE-2017-5085 Google Chrome for iOS 跨站脚本漏洞
CVE-2017-5082 Google Chrome for Android credit card autofill 信息泄露漏洞
CVE-2017-5081 Google Chrome for Linux、Windows、Mac和Android 输入验证错误漏洞
CVE-2017-5080 Google Chrome credit card autofill 安全漏洞
CVE-2017-5079 Google Chrome for Linux、Windows、Mac和Android Blink 输入验证错误漏洞
CVE-2017-5078 Google Chrome for Mac、Windows和Linux Blink 命令注入漏洞
CVE-2017-5083 Google Chrome for Linux、Windows、Mac和Android Blink 输入验证错误漏洞
CVE-2017-5089 Google Chrome for Mac Omnibox 输入验证错误漏洞
CVE-2017-5088 Google Chrome for Linux、Windows、Mac和Android V8 输入验证错误漏洞
CVE-2017-5091 Google Chrome for Linux、Windows、Mac和Android IndexedDB 安全漏洞
CVE-2017-5092 Google Chrome for Windows PPAPI插件安全漏洞
CVE-2017-5093 Google Chrome for Linux、Windows、Mac和Android Blink 安全漏洞
CVE-2017-5094 Google Chrome for Linux、Windows、Mac和Android extensions 安全漏洞
CVE-2017-5095 Google Chrome for Mac、Windows和Linux PDFium 缓冲区错误漏洞
CVE-2017-5096 Google Chrome for Android 安全漏洞
CVE-2017-5097 Google Chrome for Linux Skia 安全漏洞
CVE-2017-5098 Google Chrome for Linux、Windows、Mac和Android V8 安全漏洞
CVE-2017-5099 Google Chrome for Mac PPAPI插件安全漏洞

Showing top 20 of 91 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-5105

No comments yet


Leave a comment