CVE-2010-0661
published 2010-02-18CVE-2010-0661: WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.59%
72.9th percentile
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | webkit | — | — |
| chrome | <= 4.0.249.0 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 Same Origin Policy access control (ID 52401 / Nessus ID 44317)
vuldb·2026-05-01·CVSS 6.8
CVE-2010-0661 [MEDIUM] Google Chrome up to 2.0.172.32 Same Origin Policy access control (ID 52401 / Nessus ID 44317)
A vulnerability has been found in Google Chrome up to 2.0.172.32 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Same Origin Policy. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2010-0661. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-p5w3-55x8-h8jw: WebCore/bindings/v8/custom/V8DOMWindowCustom
ghsa_unreviewed·2022-05-02
CVE-2010-0661 [MEDIUM] GHSA-p5w3-55x8-h8jw: WebCore/bindings/v8/custom/V8DOMWindowCustom
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
Red Hat
webkit: remote bypass of same origin policy
vendor_redhat·2010-02-03·CVSS 6.8
CVE-2010-0661 [MEDIUM] webkit: remote bypass of same origin policy
webkit: remote bypass of same origin policy
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=30660http://flock.com/security/http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/52401http://www.vupen.com/english/advisories/2011/0212https://bugs.webkit.org/show_bug.cgi?id=32647https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14482http://code.google.com/p/chromium/issues/detail?id=30660http://flock.com/security/http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/52401http://www.vupen.com/english/advisories/2011/0212https://bugs.webkit.org/show_bug.cgi?id=32647https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14482
2010-02-18
Published