CVE-2017-17859
Last modified
CVE-2017-17859 is a vulnerability of currently unknown severity. Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a document.domain value corresponding to the domain that is hosting the MHTML file, but instead has a document.domain value corresponding to an arbitrary URL within the content of the MHTML file.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a document.domain value corresponding to the domain that is hosting the MHTML file, but instead has a document.domain value corresponding to an arbitrary URL within the content of the MHTML file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Internet Browser | 6.2.01.12 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17859?
How severe is CVE-2017-17859?
How do I fix CVE-2017-17859?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-17853kernel/bpf/verifier.c in the Linux kernel through 4.14.8 all…7.8
- CVE-2017-17854kernel/bpf/verifier.c in the Linux kernel through 4.14.8 all…7.8
- CVE-2017-17855kernel/bpf/verifier.c in the Linux kernel through 4.14.8 all…7.8
- CVE-2017-17856kernel/bpf/verifier.c in the Linux kernel through 4.14.8 all…7.8
- CVE-2017-17857The check_stack_boundary function in kernel/bpf/verifier.c i…7.8
- CVE-2017-17858Heap-based buffer overflow in the ensure_solid_xref function…
- CVE-2017-1786IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 u…
- CVE-2017-17860In Samsung Gear products, Bluetooth link key is updated to t…
- CVE-2017-17862kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ign…
- CVE-2017-17863kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.…
- CVE-2017-17864kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mis…
- CVE-2017-17866pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles ce…
Are you affected by CVE-2017-17859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
