CVE
- Id
- 40699
- CVE No.
- CVE-2009-3264
- Status
- Candidate
- Description
- The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user"s visit to a different web server that hosts an SVG document.
- Phase
- Assigned (20090918)
- Votes
- None (candidate not yet proposed)
- Comments