CVE
- Id
- 43240
- CVE No.
- CVE-2010-0656
- Status
- Candidate
- Description
- WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
- Phase
- Assigned (20100218)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 471154 | 43240 | CVE-2010-0656 | CONFIRM:http://code.google.com/p/chromium/issues/detail?id=20450 | View |
| 471155 | 43240 | CVE-2010-0656 | CONFIRM:http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html | View |
| 471156 | 43240 | CVE-2010-0656 | CONFIRM:http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs | View |
| 471157 | 43240 | CVE-2010-0656 | CONFIRM:http://trac.webkit.org/changeset/51295 | View |
| 471158 | 43240 | CVE-2010-0656 | CONFIRM:https://bugs.webkit.org/show_bug.cgi?id=31329 | View |
| 471159 | 43240 | CVE-2010-0656 | FEDORA:FEDORA-2010-8360 | View |
| 471160 | 43240 | CVE-2010-0656 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html | View |
| 471161 | 43240 | CVE-2010-0656 | FEDORA:FEDORA-2010-8379 | View |
| 471162 | 43240 | CVE-2010-0656 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html | View |
| 471163 | 43240 | CVE-2010-0656 | FEDORA:FEDORA-2010-8423 | View |
| 471164 | 43240 | CVE-2010-0656 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html | View |
| 471165 | 43240 | CVE-2010-0656 | MANDRIVA:MDVSA-2011:039 | View |
| 471166 | 43240 | CVE-2010-0656 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 | View |
| 471167 | 43240 | CVE-2010-0656 | SUSE:SUSE-SR:2011:002 | View |
| 471168 | 43240 | CVE-2010-0656 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html | View |
| 471169 | 43240 | CVE-2010-0656 | UBUNTU:USN-1006-1 | View |
| 471170 | 43240 | CVE-2010-0656 | URL:http://www.ubuntu.com/usn/USN-1006-1 | View |
| 471171 | 43240 | CVE-2010-0656 | BID:38372 | View |
| 471172 | 43240 | CVE-2010-0656 | URL:http://www.securityfocus.com/bid/38372 | View |
| 471173 | 43240 | CVE-2010-0656 | OVAL:oval:org.mitre.oval:def:14501 | View |
| 471174 | 43240 | CVE-2010-0656 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14501 | View |
| 471175 | 43240 | CVE-2010-0656 | SECTRACK:1023506 | View |
| 471176 | 43240 | CVE-2010-0656 | URL:http://securitytracker.com/id?1023506 | View |
| 471177 | 43240 | CVE-2010-0656 | SECUNIA:41856 | View |
| 471178 | 43240 | CVE-2010-0656 | URL:http://secunia.com/advisories/41856 | View |
| 471179 | 43240 | CVE-2010-0656 | SECUNIA:43068 | View |
| 471180 | 43240 | CVE-2010-0656 | URL:http://secunia.com/advisories/43068 | View |
| 471181 | 43240 | CVE-2010-0656 | VUPEN:ADV-2010-2722 | View |
| 471182 | 43240 | CVE-2010-0656 | URL:http://www.vupen.com/english/advisories/2010/2722 | View |
| 471183 | 43240 | CVE-2010-0656 | VUPEN:ADV-2011-0212 | View |
| 471184 | 43240 | CVE-2010-0656 | URL:http://www.vupen.com/english/advisories/2011/0212 | View |
| 471185 | 43240 | CVE-2010-0656 | VUPEN:ADV-2011-0552 | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 36610 | JVNDB-2010-002390 | Google Chrome における重要な情報を取得される脆弱性 | Google Chrome には、https から http へリダイレクトされる際、http リクエストの Referer ヘッダが https の URL を送付するため、重要な情報を取得される脆弱性が存在します。 | CVE-2010-0660 | 43240 | 5 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002390.html | View |