CVE-2013-2908Google Chrome vulnerability

2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
0.6%
top 31.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 2
Latest updateMay 17

Description

Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, which allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDgoogle/chrome30.0.1599.65+58

🔴Vulnerability Details

1
GHSA
GHSA-3x3m-9vp5-g9xh: Google Chrome before 302022-05-17
CVE-2013-2908 — Google Chrome vulnerability | cvebase