Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-6753

Quick assessment

Affected
n/a Cisco WebEx Browser Extension
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Google Chrome for Windows是美国谷歌(Google)公司开发的一款基于Windows的Web浏览器。Mozilla Firefox for Windows是美国Mozilla基金会的一款基于Windows平台的开源Web浏览器。Cisco WebEx Browser Extension是应用在其中的一个美国思科(Cisco)公司的在线会议扩展插件。 基于Windows平台的Google Chrome和Mozilla firefox上的Cisco WebEx Browser Exte

AI Predicted 8.1 Difficulty: Trivial EPSS 5.95% · P93
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-6753

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Google Chrome和Mozilla firefox for Windows Cisco WebEx Browser Extension 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Chrome for Windows是美国谷歌(Google)公司开发的一款基于Windows的Web浏览器。Mozilla Firefox for Windows是美国Mozilla基金会的一款基于Windows平台的开源Web浏览器。Cisco WebEx Browser Extension是应用在其中的一个美国思科(Cisco)公司的在线会议扩展插件。 基于Windows平台的Google Chrome和Mozilla firefox上的Cisco WebEx Browser Exte
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Cisco WebEx Browser Extension Cisco WebEx Browser Extension -

II. Public POCs for CVE-2017-6753

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-6753

登录查看更多情报信息。

Vendor Advisories for CVE-2017-6753 (5)

Same Patch Batch · n/a · 2017-07-25 · 54 CVEs total

CVE-2017-8919 NetApp OnCommand API Services 安全漏洞
CVE-2017-11627 QPDF 安全漏洞
CVE-2016-6133 Ektron Content Management System 跨站脚本漏洞
CVE-2017-11625 QPDF 安全漏洞
CVE-2017-11624 QPDF 安全漏洞
CVE-2017-9233 libexpat 安全漏洞
CVE-2017-11626 QPDF 安全漏洞
CVE-2017-6672 Cisco ASR 5000 Series Aggregation Services路由器安全漏洞
CVE-2017-6612 Cisco ASR 5000 Series Aggregation Services路由器安全漏洞
CVE-2017-9413 Subsonic 跨站请求伪造漏洞
CVE-2017-6746 Cisco Web Security Appliance AsyncOS Software 安全漏洞
CVE-2017-11460 SAP NetWeaver Portal 跨站脚本漏洞
CVE-2017-11459 SAP TREX 代码注入漏洞
CVE-2017-11458 SAP NetWeaver AS JAVA 跨站脚本安全漏洞
CVE-2017-11457 SAP NetWeaver AS JAVA 安全漏洞
CVE-2017-11434 QEMU 安全漏洞
CVE-2016-10401 ZyXEL PK5001Z设备安全漏洞
CVE-2015-8013 OpenPGP.js 加密问题漏洞
CVE-2015-6585 Hancom Hangul Word Processor 缓冲区错误漏洞
CVE-2015-5594 ZenPhoto 跨站脚本漏洞

Showing top 20 of 54 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-6753

No comments yet


Leave a comment