CVE-2009-0411
published 2009-02-03CVE-2009-0411: Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows…
PriorityP416medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.03%
60.5th percentile
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 1.0.154.43 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://codereview.chromium.org/11264http://codereview.chromium.org/18533http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-noteshttp://src.chromium.org/viewvc/chrome?view=rev&revision=8529https://exchange.xforce.ibmcloud.com/vulnerabilities/48554http://codereview.chromium.org/11264http://codereview.chromium.org/18533http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-noteshttp://src.chromium.org/viewvc/chrome?view=rev&revision=8529https://exchange.xforce.ibmcloud.com/vulnerabilities/48554
2009-02-03
Published