Логотип exploitDog
bind:CVE-2016-1617
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-1617

Количество 8

Количество 8

ubuntu логотип

CVE-2016-1617

около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-1617

около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-1617

около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-1617

около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/ ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wgvw-9qxr-cvw2

больше 3 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2016-00402

около 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю определить, какой веб-сайт был посещен с использованием HSTS-соединения

CVSS2: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0250-1

около 10 лет назад

Security update for Chromium

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0249-1

около 10 лет назад

Security update for Chromium

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-1617

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
1%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-1617

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS2: 4.3
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-1617

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
1%
Низкий
около 10 лет назад
debian логотип
CVE-2016-1617

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/ ...

CVSS3: 4.3
1%
Низкий
около 10 лет назад
github логотип
GHSA-wgvw-9qxr-cvw2

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2016-00402

Уязвимость браузера Google Chrome, позволяющая нарушителю определить, какой веб-сайт был посещен с использованием HSTS-соединения

CVSS2: 4.3
1%
Низкий
около 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0250-1

Security update for Chromium

около 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0249-1

Security update for Chromium

около 10 лет назад

Уязвимостей на страницу