CVE-2010-0556
published 2010-02-18CVE-2010-0556: browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.05%
60.4th percentile
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 4.0.249.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 Password Manager login_prompt.cc Stored credentials management (Nessus ID 44587 / ID 116891)
vuldb·2026-04-30·CVSS 4.3
CVE-2010-0556 [MEDIUM] Google Chrome up to 2.0.172.32 Password Manager login_prompt.cc Stored credentials management (Nessus ID 44587 / ID 116891)
A vulnerability described as problematic has been identified in Google Chrome up to 2.0.172.32. This vulnerability affects unknown code of the file browser/login/login_prompt.cc of the component Password Manager. Executing a manipulation can lead to credentials management (Stored).
This vulnerability appears as CVE-2010-0556. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
GHSA-8wq4-qwwj-mvjj: browser/login/login_prompt
ghsa_unreviewed·2022-05-02
CVE-2010-0556 [MEDIUM] GHSA-8wq4-qwwj-mvjj: browser/login/login_prompt
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=32718http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62319http://www.securityfocus.com/archive/1/509543/100/0/threadedhttp://www.securityfocus.com/bid/38177http://www.vsecurity.com/advisory/20100215-1.txthttp://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56216https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14407http://code.google.com/p/chromium/issues/detail?id=32718http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62319http://www.securityfocus.com/archive/1/509543/100/0/threadedhttp://www.securityfocus.com/bid/38177http://www.vsecurity.com/advisory/20100215-1.txthttp://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56216https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14407
2010-02-18
Published