CVE-2017-5081

Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
ChromeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
googlechrome
𝑥
< 59.0.3071.86
debiandebian_linux
9.0
googlechrome
𝑥
< 59.0.3071.92
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_workstation
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
cosmic
Fixed 59.0.3071.109-0ubuntu1.1360
released
bionic
Fixed 59.0.3071.109-0ubuntu1.1360
released
artful
Fixed 59.0.3071.109-0ubuntu1.1360
released
zesty
Fixed 59.0.3071.109-0ubuntu0.17.04.1360
released
yakkety
Fixed 59.0.3071.109-0ubuntu0.16.10.1357
released
xenial
Fixed 59.0.3071.109-0ubuntu0.16.04.1289
released
trusty
Fixed 59.0.3071.109-0ubuntu0.14.04.1186
released
oxide-qt
cosmic
dne
bionic
dne
artful
ignored
zesty
ignored
yakkety
ignored
xenial
ignored
trusty
dne