Total vulnerabilities in the database
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.
Software | From | Fixed in |
---|---|---|
google / chrome | 0.3.154.3 | 0.3.154.3.x |
google / chrome | 0.4.154.31 | 0.4.154.31.x |
google / chrome | 1.0.154.39 | 1.0.154.39.x |
google / chrome | 0.4.154.33 | 0.4.154.33.x |
google / chrome | 1.0.154.42 | 1.0.154.42.x |
google / chrome | - | 1.0.154.43.x |
google / chrome | 0.4.154.18 | 0.4.154.18.x |
google / chrome | 0.2.152.1 | 0.2.152.1.x |
google / chrome | 0.3.154.0 | 0.3.154.0.x |
google / chrome | 0.2.153.1 | 0.2.153.1.x |
google / chrome | 1.0.154.36 | 1.0.154.36.x |
google / chrome | 0.4.154.22 | 0.4.154.22.x |