oval:org.mitre.oval:def:26612

Definition Id: oval:org.mitre.oval:def:26612
 
Oval ID: oval:org.mitre.oval:def:26612
Title: Allows man-in-the-middle attackers to overwrite or delete arbitrary cookies
Description: Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.
Family: windows Class: vulnerability
Reference(s): CVE-2008-7294
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:11914
 
Oval ID: oval:org.mitre.oval:def:11914
Title: Google Chrome is installed
Description: Google Chrome is installed
Family: windows Class: inventory
Reference(s): cpe:/a:google:chrome
Version: 20
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): Google Chrome
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:26612