Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-1767

Опубликовано: 24 сент. 2010
Источник: debian
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkitfixed1.2.1-3package
webkitno-dsalennypackage
chromium-browserfixed5.0.375.29~r46008-1package

Примечания

  • https://bugs.webkit.org/show_bug.cgi?id=36843

  • http://trac.webkit.org/changeset/57041

EPSS

Процентиль: 58%
0.00958
Низкий

Связанные уязвимости

ubuntu
почти 16 лет назад

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

nvd
почти 16 лет назад

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

github
около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

EPSS

Процентиль: 58%
0.00958
Низкий