Lucene search

K
nvd[email protected]NVD:CVE-2012-2899
HistoryJan 05, 2014 - 8:55 p.m.

CVE-2012-2899

2014-01-0520:55:03
CWE-79
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.9%

Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors involving the document.write method.

Affected configurations

NVD
Node
googlechromeRange≤21.0.1180.81
OR
googlechromeMatch21.0.1180.0
OR
googlechromeMatch21.0.1180.1
OR
googlechromeMatch21.0.1180.2
OR
googlechromeMatch21.0.1180.31
OR
googlechromeMatch21.0.1180.32
OR
googlechromeMatch21.0.1180.33
OR
googlechromeMatch21.0.1180.34
OR
googlechromeMatch21.0.1180.35
OR
googlechromeMatch21.0.1180.36
OR
googlechromeMatch21.0.1180.37
OR
googlechromeMatch21.0.1180.38
OR
googlechromeMatch21.0.1180.39
OR
googlechromeMatch21.0.1180.41
OR
googlechromeMatch21.0.1180.46
OR
googlechromeMatch21.0.1180.47
OR
googlechromeMatch21.0.1180.48
OR
googlechromeMatch21.0.1180.49
OR
googlechromeMatch21.0.1180.50
OR
googlechromeMatch21.0.1180.51
OR
googlechromeMatch21.0.1180.52
OR
googlechromeMatch21.0.1180.53
OR
googlechromeMatch21.0.1180.54
OR
googlechromeMatch21.0.1180.55
OR
googlechromeMatch21.0.1180.56
OR
googlechromeMatch21.0.1180.57
OR
googlechromeMatch21.0.1180.59
OR
googlechromeMatch21.0.1180.60
OR
googlechromeMatch21.0.1180.61
OR
googlechromeMatch21.0.1180.62
OR
googlechromeMatch21.0.1180.63
OR
googlechromeMatch21.0.1180.64
OR
googlechromeMatch21.0.1180.68
OR
googlechromeMatch21.0.1180.69
OR
googlechromeMatch21.0.1180.70
OR
googlechromeMatch21.0.1180.71
OR
googlechromeMatch21.0.1180.72
OR
googlechromeMatch21.0.1180.73
OR
googlechromeMatch21.0.1180.74
OR
googlechromeMatch21.0.1180.75
OR
googlechromeMatch21.0.1180.76
OR
googlechromeMatch21.0.1180.77
OR
googlechromeMatch21.0.1180.78
OR
googlechromeMatch21.0.1180.79
OR
googlechromeMatch21.0.1180.80
AND
appleipad2Match-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.9%