Vulnerabilities > Google > Chrome > 4.0.249.78

DATE CVE VULNERABILITY TITLE RISK
2010-02-18 CVE-2010-0556 Credentials Management vulnerability in Google Chrome
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.
network
google CWE-255
4.3
2010-01-14 CVE-2010-0315 Multiple Security vulnerability in Google Chrome prior to 4.0.249.89
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
network
low complexity
google
5.0