5

CVE-2009-0276

Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.

Data is provided by the National Vulnerability Database (NVD)
GoogleChrome Version <= 1.0.154.43
GoogleChrome Version0.2.152.1
GoogleChrome Version0.2.153.1
GoogleChrome Version0.3.154.0
GoogleChrome Version0.3.154.3
GoogleChrome Version0.4.154.18
GoogleChrome Version0.4.154.22
GoogleChrome Version0.4.154.31
GoogleChrome Version0.4.154.33
GoogleChrome Version1.0.154.36
GoogleChrome Version1.0.154.39
GoogleChrome Version1.0.154.42
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.477
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N