Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78h8-qhmw-gr92

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

EPSS

Процентиль: 59%
0.00989
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

redhat
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

nvd
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

debian
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 ...

fstec
около 11 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю подменить данные

EPSS

Процентиль: 59%
0.00989
Низкий