CVE-2005-4900

MEDIUM

Google Chrome < 47.0.2526.111 - Inadequate Encryption Strength via SHA-1 Collision

Title source: llm
STIX 2.1

Description

SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.

References (11)

Core 11
Core References
Third Party Advisory x_refsource_misc
https://sites.google.com/site/itstheshappening
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12577
Various Sources x_refsource_misc
http://shattered.io/
Third Party Advisory x_refsource_misc
http://ia.cr/2007/474

Scores

CVSS v3 5.9
EPSS 0.0094
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326 CWE-327
Status published
Products (1)
google/chrome < 47.0.2526.111
Published Oct 14, 2016
Tracked Since Feb 18, 2026