CVE-2011-2361

Google Chrome < 13.0.782.107 - Credential Capture via Basic Authentication Dialog

Title source: llm
STIX 2.1

Description

The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.

References (5)

Core 5
Core References
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14595
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68943
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/74231

Scores

EPSS 0.0084
EPSS Percentile 53.2%

Details

CWE
CWE-287
Status published
Products (1)
google/chrome < 13.0.782.107
Published Aug 03, 2011
Tracked Since Feb 18, 2026