VDB
CVE-2013-6166
CVE-2013-6166
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.
EPSS 1.86% · 78.2th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
1.86%
78.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome | 0 | |
| n/a | n/a | n/a |
Timeline
- Apr 4, 2013 PoC Published
- Feb 15, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Jul 30, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- [oss-security] 20131017 Re: browser document.cookie DoS vulnerability mailing-list
- [oss-security] 20131016 Re: browser document.cookie DoS vulnerability mailing-list
- [oss-security] 20130403 browser document.cookie DoS vulnerability mailing-list
- http://redmine.lighttpd.net/issues/2188 url
- https://code.google.com/p/chromium/issues/detail?id=238041 url
- https://nvd.nist.gov/vuln/detail/CVE-2013-6166 advisory