Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-6636
HistoryDec 07, 2013 - 12:55 a.m.

Design/Logic Flaw

2013-12-0700:55:00
PRIOn knowledge base
www.prio-n.com
8

6.5 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.0%

The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote attackers to spoof the address bar via vectors involving the document.write method.

6.5 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.0%