Lucene search

K
cveMitreCVE-2011-1190
HistoryMar 11, 2011 - 2:01 a.m.

CVE-2011-1190

2011-03-1102:01:19
CWE-200
mitre
web.nvd.nist.gov
38
google chrome
web workers
same origin policy
bypass
cve-2011-1190
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.2

Confidence

High

EPSS

0.004

Percentile

75.3%

The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an “error message leak.”

Affected configurations

Nvd
Node
googlechromeRange<10.0.648.127
Node
applesafariRange<5.0.6
OR
appleiphone_osRange<5.0
VendorProductVersionCPE
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
applesafari*cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.2

Confidence

High

EPSS

0.004

Percentile

75.3%