Lucene search

K
cveMitreCVE-2010-4483
HistoryDec 07, 2010 - 9:00 p.m.

CVE-2010-4483

2010-12-0721:00:08
CWE-264
mitre
web.nvd.nist.gov
27
google chrome
same origin policy
video data
cve-2010-4483
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

65.2%

Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.

Affected configurations

Nvd
Node
googlechromeRange8.0.552.214
VendorProductVersionCPE
googlechromecpe:/a:google:chrome::::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

65.2%