Lucene search

K
cveMitreCVE-2010-3417
HistorySep 16, 2010 - 9:00 p.m.

CVE-2010-3417

2010-09-1621:00:02
CWE-200
mitre
web.nvd.nist.gov
31
cve-2010-3417
google chrome
access control
history
security vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

45.7%

Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors.

Affected configurations

Nvd
Node
googlechromeRange<6.0.472.59
VendorProductVersionCPE
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

45.7%