Описание
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Patch
- Vendor Advisory
- Patch
Уязвимые конфигурации
Одновременно
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r524 ...
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
EPSS
6.8 Medium
CVSS2