Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0660 | First vendor Publication | 2010-02-18 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0660 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-200 | Information Exposure |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14247 | |||
Oval ID: | oval:org.mitre.oval:def:14247 | ||
Title: | Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging. | ||
Description: | Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-0660 | Version: | 15 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Google Chrome |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2010-02-22 | Name : Google Chrome Multiple Vulnerabilities - (Win) File : nvt/secpod_google_chrome_mult_vuln_win01.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
62312 | Google Chrome Corner Case Referer Header Stripping Information Disclosure |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-01-26 | Name : The remote host contains a web browser that is affected by multiple vulnerabi... File : google_chrome_4_0_249_78.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:21 |
|
2024-11-28 12:21:16 |
|
2021-05-05 01:06:46 |
|
2021-05-04 12:11:11 |
|
2021-04-22 01:11:44 |
|
2020-09-29 01:05:18 |
|
2020-05-23 01:41:43 |
|
2020-05-23 00:25:20 |
|
2017-09-19 09:23:40 |
|
2016-04-26 19:35:59 |
|
2014-02-17 10:54:01 |
|
2013-05-10 23:18:50 |
|