Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-3956

Опубликовано: 09 фев. 2012
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 17.0.963.46 (исключая)

EPSS

Процентиль: 29%
0.00104
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-346

Связанные уязвимости

ubuntu
почти 14 лет назад

The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.

debian
почти 14 лет назад

The extension implementation in Google Chrome before 17.0.963.46 does ...

github
больше 3 лет назад

The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.

EPSS

Процентиль: 29%
0.00104
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-346