Vulnerabilities > CVE-2010-4033 - Unspecified vulnerability in Google Chrome
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN google
nessus
Summary
Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | GOOGLE_CHROME_7_0_517_41.NASL |
description | The version of Google Chrome installed on the remote host is earlier than 7.0.517.41. Such versions are reportedly affected by multiple vulnerabilities : - It is possible to spam profiles via autofill / autocomplete. (Issue #48225, #51727) - An unspecified crash exists relating to forms. (Issue #48857) - A browser crash exists relating to form autofill. (Issue #50428) - It is possible to spoof the URL on page unload. (Issue #51680) - It is possible to bypass the pop-up blocker. (Issue #53002) - A crash on shutdown exists relating to Web Sockets. (Issue #53985) - A possible memory corruption exists with animated GIF files. (Issue #54500) - Stale elements exists in the element map. (Issue #56451) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 50049 |
published | 2010-10-20 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/50049 |
title | Google Chrome < 7.0.517.41 Multiple Vulnerabilities |
code |
|
Oval
accepted | 2013-08-12T04:10:04.715-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:7159 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2010-10-25T17:24:22 | ||||||||||||||||||||||||
title | Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality | ||||||||||||||||||||||||
version | 51 |
References
- http://code.google.com/p/chromium/issues/detail?id=51727
- http://www.vupen.com/english/advisories/2010/2731
- http://www.securityfocus.com/bid/44241
- http://secunia.com/advisories/41888
- http://code.google.com/p/chromium/issues/detail?id=48225
- http://googlechromereleases.blogspot.com/2010/10/stable-channel-update.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7159