CVE-2010-0556
- EPSS 0.31%
- Veröffentlicht 18.02.2010 17:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive inf...
- EPSS 12.54%
- Veröffentlicht 14.01.2010 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK elem...
CVE-2009-2816
- EPSS 2.15%
- Veröffentlicht 13.11.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight,...
CVE-2009-3931
- EPSS 4.52%
- Veröffentlicht 12.11.2009 17:54:58
- Zuletzt bearbeitet 09.04.2025 00:30:58
Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by...
CVE-2009-3932
- EPSS 7.11%
- Veröffentlicht 12.11.2009 17:54:58
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to puttin...
CVE-2009-3934
- EPSS 1.43%
- Veröffentlicht 12.11.2009 17:54:58
- Zuletzt bearbeitet 09.04.2025 00:30:58
The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, relate...
CVE-2009-3456
- EPSS 0.06%
- Veröffentlicht 29.09.2009 18:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a ...
- EPSS 1.68%
- Veröffentlicht 18.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.
CVE-2009-3263
- EPSS 0.39%
- Veröffentlicht 18.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as...
CVE-2009-3264
- EPSS 0.18%
- Veröffentlicht 18.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit...