CVE-2017-5117 describes a vulnerability in Google Chrome versions prior to 61.0.3163.79 on Linux and Windows, where an uninitialized value in Skia could allow a remote attacker to extract sensitive information from process memory. This medium-severity vulnerability (CVSS 6.5) requires user interaction (UI:R) via a crafted HTML page, but has high confidentiality impact (C:H). While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 61.0.3163.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.