Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
References
Link | Resource |
---|---|
http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html | Third Party Advisory |
http://code.google.com/p/chromium/issues/detail?id=33445 | Vendor Advisory |
http://code.google.com/p/chromium/issues/detail?id=30801 | Vendor Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14292 | Third Party Advisory |
Configurations
Information
Published : 2010-04-01 15:30
Updated : 2018-11-16 08:28
NVD link : CVE-2010-1230
Mitre link : CVE-2010-1230
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
- chrome