Description
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
References (12)
Core 12
Core References
Third Party Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2722
Exploit, Patch, Vendor Advisory x_refsource_confirm
http://code.google.com/p/chromium/issues/detail?id=49964
Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1006-1
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/41856
Third Party Advisory vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11953
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0216
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43086
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/44203
Third Party Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0177.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0552
Scores
EPSS
0.0181
EPSS Percentile
76.3%
Details
Status
published
Products (5)
canonical/ubuntu_linux
9.10
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
10.10
google/chrome
< 5.0.375.127
webkitgtk/webkitgtk
< 1.2.6
Published
Aug 24, 2010
Tracked Since
Feb 18, 2026