CVE-2010-0656
published 2010-02-18CVE-2010-0656: WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.15%
63.2th percentile
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | webkit | <= r51280 | — |
| chrome | <= 4.0.249.78 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 information disclosure (ID 51295 / Nessus ID 47487)
vuldb·2026-05-01·CVSS 4.3
CVE-2010-0656 [MEDIUM] Google Chrome up to 2.0.172.32 information disclosure (ID 51295 / Nessus ID 47487)
A vulnerability described as problematic has been identified in Google Chrome up to 2.0.172.32. The affected element is an unknown function. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2010-0656. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-g5q4-36jf-94r5: WebKit before r51295, as used in Google Chrome before 4
ghsa_unreviewed·2022-05-02
CVE-2010-0656 [MEDIUM] CWE-200 GHSA-g5q4-36jf-94r5: WebKit before r51295, as used in Google Chrome before 4
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
Red Hat
webkit: possible information disclosure via xhr for file:/// URLs
vendor_redhat·2009-08-27·CVSS 4.3
CVE-2010-0656 [MEDIUM] webkit: possible information disclosure via xhr for file:/// URLs
webkit: possible information disclosure via xhr for file:/// URLs
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=20450http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/51295http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/38372http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=31329https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14501http://code.google.com/p/chromium/issues/detail?id=20450http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/51295http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/38372http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=31329https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14501
2010-02-18
Published