CVE-2010-0660
published 2010-02-18CVE-2010-0660: Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which…
PriorityP418medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
0.76%
51.6th percentile
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.5 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| chrome | <= 4.0.249.0 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 HTTP Logging information disclosure (Nessus ID 44317 / ID 116835)
vuldb·2026-05-01·CVSS 5.0
CVE-2010-0660 [MEDIUM] Google Chrome up to 2.0.172.32 HTTP Logging information disclosure (Nessus ID 44317 / ID 116835)
A vulnerability, which was classified as problematic, was found in Google Chrome up to 2.0.172.32. Affected is an unknown function of the component HTTP Logging. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2010-0660. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-fwr5-69f6-qxfg: WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2010-1406 [MEDIUM] CWE-200 GHSA-fwr5-69f6-qxfg: WebKit in Apple Safari before 5
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging, a related issue to CVE-2010-0660.
GHSA
GHSA-pp5x-jfjw-9p5x: Google Chrome before 4
ghsa_unreviewed·2022-05-02
CVE-2010-0660 [MEDIUM] CWE-200 GHSA-pp5x-jfjw-9p5x: Google Chrome before 4
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=29920http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14247http://code.google.com/p/chromium/issues/detail?id=29920http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14247
2010-02-18
Published