CVE Vulnerabilities

CVE-2010-0661

Published: Feb 18, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.

Affected Software

NameVendorStart VersionEnd Version
WebkitApple52400 (including)52400 (including)
Qt4-x11Ubuntuintrepid*
Qt4-x11Ubuntujaunty*
Qt4-x11Ubuntukarmic*
Qt4-x11Ubuntulucid*

References