CVE-2010-1851
- EPSS 0.09%
- Published 07.05.2010 18:24:16
- Last modified 11.04.2025 00:51:21
Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request l...
CVE-2010-1731
- EPSS 0.29%
- Published 06.05.2010 14:53:01
- Last modified 11.04.2025 00:51:21
Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.
- EPSS 7.18%
- Published 03.05.2010 13:51:53
- Last modified 11.04.2025 00:51:21
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
- EPSS 1.88%
- Published 03.05.2010 13:51:53
- Last modified 11.04.2025 00:51:21
Google Chrome before 4.1.249.1064 does not properly handle HTML5 media, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.
CVE-2010-1665
- EPSS 1.88%
- Published 03.05.2010 13:51:53
- Last modified 11.04.2025 00:51:21
Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.
CVE-2010-1500
- EPSS 0.22%
- Published 23.04.2010 14:30:01
- Last modified 11.04.2025 00:51:21
Google Chrome before 4.1.249.1059 does not properly support forms, which has unknown impact and attack vectors, related to a "type confusion error."
CVE-2010-1502
- EPSS 1.3%
- Published 23.04.2010 14:30:01
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to access local files via vectors related to "developer tools."
CVE-2010-1503
- EPSS 0.36%
- Published 23.04.2010 14:30:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://net-internals URI.
CVE-2010-1504
- EPSS 0.36%
- Published 23.04.2010 14:30:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://downloads URI.
- EPSS 0.83%
- Published 23.04.2010 14:30:01
- Last modified 11.04.2025 00:51:21
Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.