Описание
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
Ссылки
- Vendor Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Broken Link
- Not Applicable
- Not Applicable
- Not Applicable
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 17.0.963.83 (исключая)
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
Конфигурация 3Версия до 5.1.7 (исключая)Версия до 5.1.1 (исключая)
Одно из
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00892
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-346
Связанные уязвимости
ubuntu
почти 14 лет назад
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
redhat
почти 14 лет назад
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
debian
почти 14 лет назад
Google Chrome before 17.0.963.83 allows remote attackers to bypass the ...
github
больше 3 лет назад
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
EPSS
Процентиль: 75%
0.00892
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-346