CVE-2010-0650
published 2010-02-18CVE-2010-0650: WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use…
PriorityP411low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.42%
82.6th percentile
WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 4.0.249.78 | 4.0.249.78 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 access control (Nessus ID 44317 / ID 116835)
vuldb·2026-04-30·CVSS 2.6
CVE-2010-0650 [LOW] Google Chrome up to 2.0.172.32 access control (Nessus ID 44317 / ID 116835)
A vulnerability was found in Google Chrome up to 2.0.172.32. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation results in improper access controls.
This vulnerability is identified as CVE-2010-0650. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-3hxx-7wff-xwh8: WebKit, as used in Google Chrome before 4
ghsa_unreviewed·2022-05-02
CVE-2010-0650 [LOW] GHSA-3hxx-7wff-xwh8: WebKit, as used in Google Chrome before 4
WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.
Red Hat
webkit: remote bypass of popup window block settings
vendor_redhat·2008-10-09·CVSS 2.6
CVE-2010-0650 [LOW] webkit: remote bypass of popup window block settings
webkit: remote bypass of popup window block settings
WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=3275http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/38373http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=21501https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13791http://code.google.com/p/chromium/issues/detail?id=3275http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/38373http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=21501https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13791
2010-02-18
Published