| Vulnerability Name: | CVE-2012-4904 (CCN-78565) | ||||||||
| Assigned: | 2012-09-12 | ||||||||
| Published: | 2012-09-12 | ||||||||
| Updated: | 2012-09-14 | ||||||||
| Summary: | Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2012-4904 Source: CCN Type: Google Chrome Releases Web site Chrome for Android Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2012/09/chrome-for-android-update.html Source: CCN Type: SA50613 Google Chrome for Android Multiple Vulnerabilities Source: CCN Type: BID-55523 Google Chrome for Android Prior to 18.0.1025308 Multiple Security Vulnerabilities Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=138035 Source: XF Type: UNKNOWN google-android-xss(78565) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||