CVE-2011-0778
published 2011-02-04CVE-2011-0778: Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via…
PriorityP334high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.40%
69.8th percentile
Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 5.0.3 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv5.8MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vh6c-5xwq-r5vw: The HTML5 drag and drop functionality in WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2011-0166 [HIGH] GHSA-vh6c-5xwq-r5vw: The HTML5 drag and drop functionality in WebKit in Apple Safari before 5
The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.
GHSA
GHSA-xr4m-cp8c-xgr2: Google Chrome before 9
ghsa_unreviewed·2022-05-17
CVE-2011-0778 [HIGH] GHSA-xr4m-cp8c-xgr2: Google Chrome before 9
Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
OSV
CVE-2011-0166: The HTML5 drag and drop functionality in WebKit in Apple Safari before 5
osv·2011-03-11·CVSS 5.8
CVE-2011-0166 [MEDIUM] CVE-2011-0166: The HTML5 drag and drop functionality in WebKit in Apple Safari before 5
The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
Red Hat
WebKit: restrict cross-origin drag+drop in WebKit
vendor_redhat·2011-02-03·CVSS 7.5
CVE-2011-0778 [HIGH] WebKit: restrict cross-origin drag+drop in WebKit
WebKit: restrict cross-origin drag+drop in WebKit
Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
Package: webkitgtk (Red Hat Enterprise Linux Extended Update Support 6.0) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
bugzilla·2011-02-09·CVSS 10.0
CVE-2010-4492 [CRITICAL] CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4493
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676201,676202
---
Adding parent bug CVE-2011-0482
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676201,676202,676203
---
Adding parent bug CVE-2010-4199
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2011-0778 WebKit: restrict cross-origin drag+drop in WebKit
bugzilla·2011-02-09·CVSS 7.5
CVE-2011-0778 [HIGH] CVE-2011-0778 WebKit: restrict cross-origin drag+drop in WebKit
CVE-2011-0778 WebKit: restrict cross-origin drag+drop in WebKit
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0778 to
the following vulnerability:
Name: CVE-2011-0778
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0778
Assigned: 20110204
Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=59081
Reference: CONFIRM:http://googlechromereleases.blogspot.com/2011/02/stable-channel-update.html
Google Chrome before 9.0.597.84 does not properly restrict drag and
drop operations, which might allow remote attackers to bypass the Same
Origin Policy via unspecified vectors.
This is fixed in webkitgtk 1.2.7
Discussion:
Created webkitgtk tracking bugs for this issue
Affects: fedora-13 [bug 676213]
http://code.google.com/p/chromium/issues/detail?id=59081http://googlechromereleases.blogspot.com/2011/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://secunia.com/advisories/43368http://www.debian.org/security/2011/dsa-2166http://www.debian.org/security/2011/dsa-2188http://www.vupen.com/english/advisories/2011/0408https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14228http://code.google.com/p/chromium/issues/detail?id=59081http://googlechromereleases.blogspot.com/2011/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://secunia.com/advisories/43368http://www.debian.org/security/2011/dsa-2166http://www.debian.org/security/2011/dsa-2188http://www.vupen.com/english/advisories/2011/0408https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14228
2011-02-04
Published