Vulnerabilities > CVE-2010-1663 - Unspecified vulnerability in Google Chrome
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Vulnerable Configurations
Exploit-Db
description | Google Chrome 4.1.249.1059 Cross Origin Bypass in Google URL (GURL). CVE-2010-1663. Remote exploit for windows platform |
id | EDB-ID:12657 |
last seen | 2016-02-01 |
modified | 2010-05-19 |
published | 2010-05-19 |
reporter | Jordi Chancel |
source | https://www.exploit-db.com/download/12657/ |
title | Google Chrome 4.1.249.1059 - Cross Origin Bypass in Google URL GURL |
Nessus
NASL family | Windows |
NASL id | GOOGLE_CHROME_4_1_249_1064.NASL |
description | The version of Google Chrome installed on the remote host is earlier than 4.1.249.1064. Such versions are reportedly affected by multiple vulnerabilities : - A cross-origin bypass in Google URL (GURL). (Issue #40445) - An HTML5 media handling issue could lead to memory corruption. (Issue #40487) - A font handling issue could lead to memory corruption. (Issue #42294) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 46171 |
published | 2010-04-28 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/46171 |
title | Google Chrome < 4.1.249.1064 Multiple Vulnerabilities |
code |
|
Oval
accepted | 2013-08-12T04:09:45.262-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:6813 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2010-09-13T19:43:23 | ||||||||||||||||||||||||
title | Allows remote attackers to bypass the Origin Policy in Google Chrome version less than 4.1.249.1064 | ||||||||||||||||||||||||
version | 51 |
Packetstorm
data source | https://packetstormsecurity.com/files/download/89715/googlechrome-crossorigin.txt |
id | PACKETSTORM:89715 |
last seen | 2016-12-05 |
published | 2010-05-20 |
reporter | Jordi Chancel |
source | https://packetstormsecurity.com/files/89715/Google-Chrome-4.1.249.1059-Cross-Origin-Bypass.html |
title | Google Chrome 4.1.249.1059 Cross Origin Bypass |
Seebug
bulletinFamily exploit description No description provided by source. id SSV:19654 last seen 2017-11-19 modified 2010-05-20 published 2010-05-20 reporter Root source https://www.seebug.org/vuldb/ssvid-19654 title Google Chrome 4.1.249.1059 Cross Origin Bypass in Google URL (GURL) bulletinFamily exploit description No description provided by source. id SSV:68653 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-68653 title Google Chrome 4.1.249.1059 - Cross Origin Bypass in Google URL (GURL)
References
- http://bugs.chromium.org/40445
- http://bugs.chromium.org/40445
- http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html
- http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html
- http://secunia.com/advisories/39651
- http://secunia.com/advisories/39651
- http://www.vupen.com/english/advisories/2010/1016
- http://www.vupen.com/english/advisories/2010/1016
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6813
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6813