Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86pj-mwrp-p73h

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

EPSS

Процентиль: 78%
0.01106
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 10 лет назад

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

redhat
больше 10 лет назад

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

nvd
больше 10 лет назад

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

debian
больше 10 лет назад

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.c ...

EPSS

Процентиль: 78%
0.01106
Низкий

Дефекты

CWE-200