CVE-2010-1236
The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \x00javascript:alert sequence.
- Affected products
- Flock Browser, Google Chrome, Webkit
- Google Chrome
- ≤ 4.1.249.1035, 0.1.38.1, 0.1.38.2, 0.1.38.4, 0.1.40.1, 0.1.42.2, 0.1.42.3, 1.0.154.53, 1.0.154.59, 1.0.154.64, 1.0.154.65, 2.0.169.0, 2.0.169.1, 2.0.170.0, 2.0.172.2, 2.0.172.8, 2.0.172.27, 2.0.172.28, 2.0.172.30, 2.0.172.33, 2.0.172.37, 2.0.172.38, 3.0.182.2, 3.0.190.2, 3.0.195.25, 3.0.195.27, 3.0.195.33, 3.0.195.36, 3.0.195.37, 3.0.195.38, 4.0.212.0, 4.0.212.1, 4.0.221.8, 4.0.222.0, 4.0.222.1, 4.0.222.5, 4.0.222.12, 4.0.223.0, 4.0.223.1, 4.0.223.2
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.3% (69th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2010-04-01
CVE-2010-1236 at NVD
No indexed exploits for CVE-2010-1236 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2010-1236 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.