// For flags

CVE-2010-0556

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.

browser/login/login_prompt.cc en Google Chrome anterior v4.0.249.89 con un diálogo de autenticación con credenciales que fueron almacenadas por Password Manager para sitios web diferentes, permite a servidores HTTP remotos asistidos por usuarios obtener información sensible a través de una URL que requiere autenticación, como quedó demostrado por una URL en el atributo SRC de un elemento IMG.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-02-05 CVE Reserved
  • 2010-02-16 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
<= 4.0.249.78
Search vendor "Google" for product "Chrome" and version " <= 4.0.249.78"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.2.149.27
Search vendor "Google" for product "Chrome" and version "0.2.149.27"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.2.149.29
Search vendor "Google" for product "Chrome" and version "0.2.149.29"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.2.149.30
Search vendor "Google" for product "Chrome" and version "0.2.149.30"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.2.152.1
Search vendor "Google" for product "Chrome" and version "0.2.152.1"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.2.153.1
Search vendor "Google" for product "Chrome" and version "0.2.153.1"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.3.154.0
Search vendor "Google" for product "Chrome" and version "0.3.154.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.3.154.3
Search vendor "Google" for product "Chrome" and version "0.3.154.3"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.4.154.18
Search vendor "Google" for product "Chrome" and version "0.4.154.18"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.4.154.22
Search vendor "Google" for product "Chrome" and version "0.4.154.22"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.4.154.31
Search vendor "Google" for product "Chrome" and version "0.4.154.31"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
0.4.154.33
Search vendor "Google" for product "Chrome" and version "0.4.154.33"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.36
Search vendor "Google" for product "Chrome" and version "1.0.154.36"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.39
Search vendor "Google" for product "Chrome" and version "1.0.154.39"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.42
Search vendor "Google" for product "Chrome" and version "1.0.154.42"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.43
Search vendor "Google" for product "Chrome" and version "1.0.154.43"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.46
Search vendor "Google" for product "Chrome" and version "1.0.154.46"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.48
Search vendor "Google" for product "Chrome" and version "1.0.154.48"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.52
Search vendor "Google" for product "Chrome" and version "1.0.154.52"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.53
Search vendor "Google" for product "Chrome" and version "1.0.154.53"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.59
Search vendor "Google" for product "Chrome" and version "1.0.154.59"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
1.0.154.65
Search vendor "Google" for product "Chrome" and version "1.0.154.65"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.156.1
Search vendor "Google" for product "Chrome" and version "2.0.156.1"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.157.0
Search vendor "Google" for product "Chrome" and version "2.0.157.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.157.2
Search vendor "Google" for product "Chrome" and version "2.0.157.2"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.158.0
Search vendor "Google" for product "Chrome" and version "2.0.158.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.159.0
Search vendor "Google" for product "Chrome" and version "2.0.159.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.169.0
Search vendor "Google" for product "Chrome" and version "2.0.169.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.169.1
Search vendor "Google" for product "Chrome" and version "2.0.169.1"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.170.0
Search vendor "Google" for product "Chrome" and version "2.0.170.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172
Search vendor "Google" for product "Chrome" and version "2.0.172"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.2
Search vendor "Google" for product "Chrome" and version "2.0.172.2"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.8
Search vendor "Google" for product "Chrome" and version "2.0.172.8"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.27
Search vendor "Google" for product "Chrome" and version "2.0.172.27"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.28
Search vendor "Google" for product "Chrome" and version "2.0.172.28"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.30
Search vendor "Google" for product "Chrome" and version "2.0.172.30"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.31
Search vendor "Google" for product "Chrome" and version "2.0.172.31"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.33
Search vendor "Google" for product "Chrome" and version "2.0.172.33"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.37
Search vendor "Google" for product "Chrome" and version "2.0.172.37"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
2.0.172.38
Search vendor "Google" for product "Chrome" and version "2.0.172.38"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.182.2
Search vendor "Google" for product "Chrome" and version "3.0.182.2"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.190.2
Search vendor "Google" for product "Chrome" and version "3.0.190.2"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.193.2
Search vendor "Google" for product "Chrome" and version "3.0.193.2"
beta
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.195.21
Search vendor "Google" for product "Chrome" and version "3.0.195.21"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.195.24
Search vendor "Google" for product "Chrome" and version "3.0.195.24"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.195.32
Search vendor "Google" for product "Chrome" and version "3.0.195.32"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
3.0.195.33
Search vendor "Google" for product "Chrome" and version "3.0.195.33"
-
Affected