5

CVE-2009-0276

Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version <= 1.0.154.43
Google ≫ Chrome Version 0.2.152.1
Google ≫ Chrome Version 0.2.153.1
Google ≫ Chrome Version 0.3.154.0
Google ≫ Chrome Version 0.3.154.3
Google ≫ Chrome Version 0.4.154.18
Google ≫ Chrome Version 0.4.154.22
Google ≫ Chrome Version 0.4.154.31
Google ≫ Chrome Version 0.4.154.33
Google ≫ Chrome Version 1.0.154.36
Google ≫ Chrome Version 1.0.154.39
Google ≫ Chrome Version 1.0.154.42
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.12% 0.625
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html
Vendor Advisory
http://secunia.com/advisories/33754
Vendor Advisory
http://codereview.chromium.org/18531
http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes
http://src.chromium.org/viewvc/chrome?view=rev&revision=8524