VDB
CVE-2010-0315
CVE-2010-0315
PUBLISHED
CVSS 5 MEDIUM
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
EPSS 6.89% · 93.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
6.89%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome | 0.3.154.0, 0, 0.2.149.30 | |
| n/a | n/a | n/a |
Timeline
- Jan 14, 2010 CVE Published
- Jan 22, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 2, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- 38177 vdb
- ADV-2011-0212 vdb
- http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs url
- google-chrome-href-info-disclosure(55683) vdb
- ADV-2010-0361 vdb
- oval:org.mitre.oval:def:14452 vdb
- 43068 third-party-advisory
- http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html url
- 1023583 vdb
- SUSE-SR:2011:002 vendor-advisory
- https://bugs.webkit.org/show_bug.cgi?id=33683 url
- https://nvd.nist.gov/vuln/detail/CVE-2010-0315 advisory
- http://trac.webkit.org/changeset/53607 url
- http://code.google.com/p/chromium/issues/detail?id=32309 technical
- http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html technical
- http://secunia.com/advisories/38545 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56215 technical