VulnerabilityModified
CVE-2010-1230
Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
HIGH 10.0EPSS 1.42%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=30801Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=33445Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.htmlThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14292Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=30801Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=33445Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.htmlThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14292Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.