Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-1627

Опубликовано: 14 фев. 2016
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 48.0.2564.103 (включая)

EPSS

Процентиль: 79%
0.01244
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 10 лет назад

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.

redhat
почти 10 лет назад

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.

CVSS3: 8.8
debian
почти 10 лет назад

The Developer Tools (aka DevTools) subsystem in Google Chrome before 4 ...

CVSS3: 8.8
github
больше 3 лет назад

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.

fstec
почти 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения доступа

EPSS

Процентиль: 79%
0.01244
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-264