Vulnerability Name: | CVE-2013-0885 (CCN-82281) | ||||||||||||||||||||||||
Assigned: | 2013-02-21 | ||||||||||||||||||||||||
Published: | 2013-02-21 | ||||||||||||||||||||||||
Updated: | 2022-11-18 | ||||||||||||||||||||||||
Summary: | Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-732 | ||||||||||||||||||||||||
Vulnerability Consequences: | Unknown | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-0885 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Release Notes, Vendor Advisory http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html Source: SUSE Type: Broken Link, Third Party Advisory openSUSE-SU-2013:0454 Source: CCN Type: SA52320 Google Chrome Multiple Vulnerabilities Source: CCN Type: BID-59334 Google Chrome CVE-2013-0885 Unspecified Security Vulnerability Source: CONFIRM Type: Permissions Required https://code.google.com/p/chromium/issues/detail?id=172369 Source: XF Type: UNKNOWN chrome-api-unspecified(82281) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:16255 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |