CVE-2011-0778Google Chrome vulnerability

CWE-2649 documents6 sources
Severity
7.5HIGHNVD
NVD5.8OSV5.8
EPSS
0.5%
top 32.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateMay 17

Description

Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDgoogle/chrome9.0.597.83
NVDapple/safari5.0.3+53

🔴Vulnerability Details

3
GHSA
GHSA-vh6c-5xwq-r5vw: The HTML5 drag and drop functionality in WebKit in Apple Safari before 52022-05-17
GHSA
GHSA-xr4m-cp8c-xgr2: Google Chrome before 92022-05-17
OSV
CVE-2011-0166: The HTML5 drag and drop functionality in WebKit in Apple Safari before 52011-03-11

📋Vendor Advisories

2
Ubuntu
WebKit vulnerabilities2011-08-23
Red Hat
WebKit: restrict cross-origin drag+drop in WebKit2011-02-03

💬Community

2
Bugzilla
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]2011-02-09
Bugzilla
CVE-2011-0778 WebKit: restrict cross-origin drag+drop in WebKit2011-02-09
CVE-2011-0778 — Google Chrome vulnerability | cvebase