Description
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-0415 | Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T04:31:26.170Z
Reserved: 2009-02-03T00:00:00.000Z
Link: CVE-2009-0411
No data.
Status : Modified
Published: 2009-02-03T19:30:00.627
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-0411
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD