CVE Vulnerabilities

CVE-2008-7294

Published: Aug 09, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a cookie forcing issue.

Affected Software

NameVendorStart VersionEnd Version
ChromeGoogle*3.0.195.38 (including)
ChromeGoogle0.1.38.1 (including)0.1.38.1 (including)
ChromeGoogle0.1.38.2 (including)0.1.38.2 (including)
ChromeGoogle0.1.38.4 (including)0.1.38.4 (including)
ChromeGoogle0.1.40.1 (including)0.1.40.1 (including)
ChromeGoogle0.1.42.2 (including)0.1.42.2 (including)
ChromeGoogle0.1.42.3 (including)0.1.42.3 (including)
ChromeGoogle0.2.149.27 (including)0.2.149.27 (including)
ChromeGoogle0.2.149.29 (including)0.2.149.29 (including)
ChromeGoogle0.2.149.30 (including)0.2.149.30 (including)
ChromeGoogle0.2.152.1 (including)0.2.152.1 (including)
ChromeGoogle0.2.153.1 (including)0.2.153.1 (including)
ChromeGoogle0.3.154.0 (including)0.3.154.0 (including)
ChromeGoogle0.3.154.3 (including)0.3.154.3 (including)
ChromeGoogle0.4.154.18 (including)0.4.154.18 (including)
ChromeGoogle0.4.154.22 (including)0.4.154.22 (including)
ChromeGoogle0.4.154.31 (including)0.4.154.31 (including)
ChromeGoogle0.4.154.33 (including)0.4.154.33 (including)
ChromeGoogle1.0.154.36 (including)1.0.154.36 (including)
ChromeGoogle1.0.154.39 (including)1.0.154.39 (including)
ChromeGoogle1.0.154.42 (including)1.0.154.42 (including)
ChromeGoogle1.0.154.43 (including)1.0.154.43 (including)
ChromeGoogle1.0.154.46 (including)1.0.154.46 (including)
ChromeGoogle1.0.154.48 (including)1.0.154.48 (including)
ChromeGoogle1.0.154.52 (including)1.0.154.52 (including)
ChromeGoogle1.0.154.53 (including)1.0.154.53 (including)
ChromeGoogle1.0.154.59 (including)1.0.154.59 (including)
ChromeGoogle1.0.154.64 (including)1.0.154.64 (including)
ChromeGoogle1.0.154.65 (including)1.0.154.65 (including)
ChromeGoogle2.0.156.1 (including)2.0.156.1 (including)
ChromeGoogle2.0.157.0 (including)2.0.157.0 (including)
ChromeGoogle2.0.157.2 (including)2.0.157.2 (including)
ChromeGoogle2.0.158.0 (including)2.0.158.0 (including)
ChromeGoogle2.0.159.0 (including)2.0.159.0 (including)
ChromeGoogle2.0.169.0 (including)2.0.169.0 (including)
ChromeGoogle2.0.169.1 (including)2.0.169.1 (including)
ChromeGoogle2.0.170.0 (including)2.0.170.0 (including)
ChromeGoogle2.0.172 (including)2.0.172 (including)
ChromeGoogle2.0.172.2 (including)2.0.172.2 (including)
ChromeGoogle2.0.172.8 (including)2.0.172.8 (including)
ChromeGoogle2.0.172.27 (including)2.0.172.27 (including)
ChromeGoogle2.0.172.28 (including)2.0.172.28 (including)
ChromeGoogle2.0.172.30 (including)2.0.172.30 (including)
ChromeGoogle2.0.172.31 (including)2.0.172.31 (including)
ChromeGoogle2.0.172.33 (including)2.0.172.33 (including)
ChromeGoogle2.0.172.37 (including)2.0.172.37 (including)
ChromeGoogle2.0.172.38 (including)2.0.172.38 (including)
ChromeGoogle3.0.182.2 (including)3.0.182.2 (including)
ChromeGoogle3.0.190.2 (including)3.0.190.2 (including)
ChromeGoogle3.0.193.2-beta (including)3.0.193.2-beta (including)
ChromeGoogle3.0.195.2 (including)3.0.195.2 (including)
ChromeGoogle3.0.195.21 (including)3.0.195.21 (including)
ChromeGoogle3.0.195.24 (including)3.0.195.24 (including)
ChromeGoogle3.0.195.25 (including)3.0.195.25 (including)
ChromeGoogle3.0.195.27 (including)3.0.195.27 (including)
ChromeGoogle3.0.195.32 (including)3.0.195.32 (including)
ChromeGoogle3.0.195.33 (including)3.0.195.33 (including)
ChromeGoogle3.0.195.36 (including)3.0.195.36 (including)
ChromeGoogle3.0.195.37 (including)3.0.195.37 (including)
Chromium-browserUbuntulucid*
Chromium-browserUbuntumaverick*
Chromium-browserUbuntunatty*
Chromium-browserUbuntuoneiric*

References