Lucene search

K
cveMitreCVE-2009-0276
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-0276

2022-10-0316:24:11
mitre
web.nvd.nist.gov
38
cve-2009-0276
cross-domain vulnerability
v8 javascript engine
google chrome
same origin policy

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

61.9%

Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.

Affected configurations

Nvd
Node
googlechromeRange1.0.154.43
OR
googlechromeMatch0.2.152.1
OR
googlechromeMatch0.2.153.1
OR
googlechromeMatch0.3.154.0
OR
googlechromeMatch0.3.154.3
OR
googlechromeMatch0.4.154.18
OR
googlechromeMatch0.4.154.22
OR
googlechromeMatch0.4.154.31
OR
googlechromeMatch0.4.154.33
OR
googlechromeMatch1.0.154.36
OR
googlechromeMatch1.0.154.39
OR
googlechromeMatch1.0.154.42
VendorProductVersionCPE
googlechrome0.4.154.22cpe:/a:google:chrome:0.4.154.22:::
googlechrome0.4.154.33cpe:/a:google:chrome:0.4.154.33:::
googlechrome0.3.154.3cpe:/a:google:chrome:0.3.154.3:::
googlechrome0.3.154.0cpe:/a:google:chrome:0.3.154.0:::
googlechrome1.0.154.39cpe:/a:google:chrome:1.0.154.39:::
googlechrome0.2.153.1cpe:/a:google:chrome:0.2.153.1:::
googlechrome0.4.154.18cpe:/a:google:chrome:0.4.154.18:::
googlechrome0.2.152.1cpe:/a:google:chrome:0.2.152.1:::
googlechrome0.4.154.31cpe:/a:google:chrome:0.4.154.31:::
googlechromecpe:/a:google:chrome::::
Rows per page:
1-10 of 121

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

61.9%