CVE-2010-0643
published 2010-02-18CVE-2010-0643: Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.01%
59.9th percentile
Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 4.0.249.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 Proxy Server information disclosure (Nessus ID 44587 / ID 116891)
vuldb·2026-04-30·CVSS 4.3
CVE-2010-0643 [MEDIUM] Google Chrome up to 2.0.172.32 Proxy Server information disclosure (Nessus ID 44587 / ID 116891)
A vulnerability classified as problematic has been found in Google Chrome up to 2.0.172.32. This issue affects some unknown processing of the component Proxy Server. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2010-0643. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-976g-x9w5-4h78: Google Chrome before 4
ghsa_unreviewed·2022-05-02
CVE-2010-0643 [MEDIUM] CWE-200 GHSA-976g-x9w5-4h78: Google Chrome before 4
Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=12303http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62315http://www.securityfocus.com/bid/38177http://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56212https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14500http://code.google.com/p/chromium/issues/detail?id=12303http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlhttp://secunia.com/advisories/38545http://securitytracker.com/id?1023583http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.osvdb.org/62315http://www.securityfocus.com/bid/38177http://www.vupen.com/english/advisories/2010/0361https://exchange.xforce.ibmcloud.com/vulnerabilities/56212https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14500
2010-02-18
Published