• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2011-1190
  1. CVEs

CVE-2011-1190

medium
  • Information
  • CPEs
  • Plugins

Description

The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."

References

http://code.google.com/p/chromium/issues/detail?id=70336

http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.html

http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html

http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html

http://support.apple.com/kb/HT4808

http://support.apple.com/kb/HT4999

http://www.securityfocus.com/bid/46785

http://www.vupen.com/english/advisories/2011/0628

https://exchange.xforce.ibmcloud.com/vulnerabilities/65954

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14398

Details

Source: MITRE

Published: 2011-03-11

Updated: 2020-06-02

Type: CWE-200

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance