4.3

CVE-2010-0643

Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.

Data is provided by the National Vulnerability Database (NVD)
GoogleChrome Version <= 4.0.249.78
GoogleChrome Version0.2.149.27
GoogleChrome Version0.2.149.29
GoogleChrome Version0.2.149.30
GoogleChrome Version0.2.152.1
GoogleChrome Version0.2.153.1
GoogleChrome Version0.3.154.0
GoogleChrome Version0.3.154.3
GoogleChrome Version0.4.154.18
GoogleChrome Version0.4.154.22
GoogleChrome Version0.4.154.31
GoogleChrome Version0.4.154.33
GoogleChrome Version1.0.154.36
GoogleChrome Version1.0.154.39
GoogleChrome Version1.0.154.42
GoogleChrome Version1.0.154.43
GoogleChrome Version1.0.154.46
GoogleChrome Version1.0.154.48
GoogleChrome Version1.0.154.52
GoogleChrome Version1.0.154.53
GoogleChrome Version1.0.154.59
GoogleChrome Version1.0.154.65
GoogleChrome Version2.0.156.1
GoogleChrome Version2.0.157.0
GoogleChrome Version2.0.157.2
GoogleChrome Version2.0.158.0
GoogleChrome Version2.0.159.0
GoogleChrome Version2.0.169.0
GoogleChrome Version2.0.169.1
GoogleChrome Version2.0.170.0
GoogleChrome Version2.0.172
GoogleChrome Version2.0.172.2
GoogleChrome Version2.0.172.8
GoogleChrome Version2.0.172.27
GoogleChrome Version2.0.172.28
GoogleChrome Version2.0.172.30
GoogleChrome Version2.0.172.31
GoogleChrome Version2.0.172.33
GoogleChrome Version2.0.172.37
GoogleChrome Version2.0.172.38
GoogleChrome Version3.0.182.2
GoogleChrome Version3.0.190.2
GoogleChrome Version3.0.193.2 Updatebeta
GoogleChrome Version3.0.195.21
GoogleChrome Version3.0.195.24
GoogleChrome Version3.0.195.32
GoogleChrome Version3.0.195.33
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.35% 0.54
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.