Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-1767

Опубликовано: 24 сент. 2010
Источник: debian
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkitfixed1.2.1-3package
webkitno-dsalennypackage
chromium-browserfixed5.0.375.29~r46008-1package

Примечания

  • https://bugs.webkit.org/show_bug.cgi?id=36843

  • http://trac.webkit.org/changeset/57041

EPSS

Процентиль: 70%
0.00632
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

nvd
больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

github
больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

EPSS

Процентиль: 70%
0.00632
Низкий