VulnerabilityModified
CVE-2010-4483
Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.
MEDIUM 4.3EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=55745
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.htmlVendor Advisory
- http://secunia.com/advisories/42472
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11610
- https://technet.microsoft.com/library/security/msvr11-002
- http://code.google.com/p/chromium/issues/detail?id=55745
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.htmlVendor Advisory
- http://secunia.com/advisories/42472
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11610
- https://technet.microsoft.com/library/security/msvr11-002
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.