Vulnerability Name: | CVE-2010-0315 (CCN-40355) |
Assigned: | 2008-02-07 |
Published: | 2008-02-07 |
Updated: | 2017-09-19 |
Summary: | WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Authentication (Au): | Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Athentication (Au):
| Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Obtain Information |
References: | Source: CCN Type: Netscape Web site Release Notes: What's New in Netscape Navigator 9.0.0.6
Source: CONFIRM Type: UNKNOWN http://code.google.com/p/chromium/issues/detail?id=32309
Source: MITRE Type: CNA CVE-2008-0593
Source: MITRE Type: CNA CVE-2010-0315
Source: CONFIRM Type: UNKNOWN http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html
Source: SUSE Type: UNKNOWN SUSE-SR:2011:002
Source: CCN Type: No More Root Blog Little bug in Safari and Google Chrome
Source: MISC Type: Exploit http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html
Source: CCN Type: RHSA-2008-0103 Critical: firefox security update
Source: CCN Type: RHSA-2008-0104 Critical: seamonkey security update
Source: CCN Type: RHSA-2008-0105 Moderate: thunderbird security update
Source: CCN Type: SA28758 Mozilla Firefox Multiple Vulnerabilities
Source: CCN Type: SA28815 Mozilla SeaMonkey Multiple Vulnerabilities
Source: CCN Type: SA29049 Netscape Multiple Vulnerabilities
Source: CCN Type: SA30620 Sun Solaris Firefox Multiple Vulnerabilities
Source: CCN Type: SA37931 Apple Safari Stylesheet Redirection Information Disclosure
Source: CCN Type: SA38061 Google Chrome Stylesheet Redirection Information Disclosure
Source: CCN Type: SA38545 Google Chrome Multiple Vulnerabilities
Source: SECUNIA Type: Vendor Advisory 38545
Source: SECUNIA Type: Vendor Advisory 43068
Source: CCN Type: SECTRACK ID: 1019341 Mozilla Firefox Stylesheet Processing Bug May Let Remote Users Obtain URL Parameters
Source: CCN Type: SECTRACK ID: 1023583 Google Chrome Bugs Let Remote Users Execute Arbitrary Code and Obtain Information
Source: SECTRACK Type: UNKNOWN 1023583
Source: CONFIRM Type: UNKNOWN http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
Source: CCN Type: Sun Alert ID: 238492 Multiple Security Vulnerabilities in Solaris 10 Firefox may Allow Execution of Arbitrary Code and Access to Unauthorized Data
Source: CCN Type: ASA-2008-058 thunderbird security update (RHSA-2008-0105)
Source: CCN Type: ASA-2008-059 firefox security update (RHSA-2008-0103)
Source: CCN Type: ASA-2008-101 seamonkey security update (RHSA-2008-0104)
Source: CONFIRM Type: UNKNOWN http://trac.webkit.org/changeset/53607
Source: DEBIAN Type: DSA-1484 xulrunner -- several vulnerabilities
Source: DEBIAN Type: DSA-1485 icedove -- several vulnerabilities
Source: DEBIAN Type: DSA-1489 iceweasel -- several vulnerabilities
Source: DEBIAN Type: DSA-1506 iceape -- several vulnerabilities
Source: CCN Type: MFSA 2008-10 URL token stealing via stylesheet redirect
Source: CCN Type: BID-27683 Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
Source: CCN Type: BID-37917 Google Chrome Style Sheet Redirection Information Disclosure Vulnerability
Source: BID Type: UNKNOWN 38177
Source: CCN Type: BID-38177 Google Chrome prior to 4.0.249.89 Multiple Security Vulnerabilities
Source: CCN Type: USN-576-1 Firefox vulnerabilities
Source: VUPEN Type: Vendor Advisory ADV-2010-0361
Source: VUPEN Type: Vendor Advisory ADV-2011-0212
Source: CONFIRM Type: UNKNOWN https://bugs.webkit.org/show_bug.cgi?id=33683
Source: CCN Type: Mozilla Bugzilla Bug 397427 [FIX]Stylesheet href property shows redirected URL unlike other browsers
Source: XF Type: UNKNOWN mozilla-stylesheet-information-disclosure(40355)
Source: XF Type: UNKNOWN google-chrome-href-info-disclosure(55683)
Source: XF Type: UNKNOWN googlechrome-iframe-info-disc(56215)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14452
Source: SUSE Type: SUSE-SA:2008:008 Mozilla Firefox and Seamonkey Security Problems
Source: SUSE Type: SUSE-SR:2011:002 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:google:chrome:0.2.149.27:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.149.29:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.149.30:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.152.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.153.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.3.154.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.3.154.3:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.18:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.22:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.31:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.36:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.39:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.42:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.43:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.46:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.48:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.52:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.53:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.59:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.65:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.156.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.157.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.157.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.158.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.159.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.169.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.169.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.170.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.8:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.27:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.28:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.30:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.31:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.37:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.38:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.182.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.190.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.193.2:beta:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.21:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.24:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.32:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version <= 4.0.249.78) Denotes that component is vulnerable |
Vulnerability Name: | CVE-2010-0315 (CCN-55683) |
Assigned: | 2010-01-09 |
Published: | 2010-01-09 |
Updated: | 2010-01-09 |
Summary: | Google Chrome could allow a remote attacker to obtain sensitive information. By placing the site's URL in the HREF attribute of a stylesheet LINK element, then reading the document.styleSheets[0].href property value, a remote attacker could exploit this vulnerability to obtain a redirected target URL for another user's session. |
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Authentication (Au): | Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Athentication (Au):
| Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): |
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2010-0315
Source: CCN Type: No More Root Blog, Jan 9, 2010 No More Root: Little bug in Safari and Google Chrome
Source: CCN Type: SA38545 Google Chrome Multiple Vulnerabilities
Source: CCN Type: SECTRACK ID: 1023583 Google Chrome Bugs Let Remote Users Execute Arbitrary Code and Obtain Information
Source: CCN Type: Google Web site Google Chrome Frame-Bring open web technologies to your browser
Source: CCN Type: BID-38177 Google Chrome prior to 4.0.249.89 Multiple Security Vulnerabilities
Source: XF Type: UNKNOWN google-chrome-href-info-disclosure(55683)
Source: SUSE Type: SUSE-SR:2011:002 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration CCN 1: cpe:/a:google:chrome:*:*:*:*:*:*:*:* Denotes that component is vulnerable |
Oval Definitions |
Definition ID | Class | Title | Last Modified |
---|
oval:org.opensuse.security:def:20100315 | V | CVE-2010-0315 | 2015-11-16 | oval:org.mitre.oval:def:14452 | V | WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element. | 2014-04-07 |
|
BACK |