← Back

CVE-2010-0657

nvd nist
Published: Feb 18, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.

Affected (46)

Products: Google: Chrome
1 product
Chrome
Configuration A
46 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Google
Version 0.2.149.27
Version 0.2.149.29
Version 0.2.149.30
Version 0.2.152.1
Version 0.2.153.1
Version 0.3.154.0
Version 0.3.154.3
Version 0.4.154.18
Version 0.4.154.22
Version 0.4.154.31
Version 0.4.154.33
Version 1.0.154.36
Version 1.0.154.39
Version 1.0.154.42
Version 1.0.154.43
Version 1.0.154.46
Version 1.0.154.48
Version 1.0.154.52
Version 1.0.154.53
Version 1.0.154.59
Version 1.0.154.65
Version 2.0.156.1
Version 2.0.157.0
Version 2.0.157.2
Version 2.0.158.0
Version 2.0.159.0
Version 2.0.169.0
Version 2.0.169.1
Version 2.0.170.0
Version 2.0.172.27
Version 2.0.172.28
Version 2.0.172.2
Version 2.0.172.30
Version 2.0.172.31
Version 2.0.172.33
Version 2.0.172.37
Version 2.0.172.38
Version 2.0.172.8
Version 2.0.172
Version 3.0.182.2
Version 3.0.190.2
Version 3.0.193.2 beta
Version 3.0.195.21
Version 3.0.195.24
Version 3.0.195.32
Version 3.0.195.33
Running on/withPlatform Versions
Google
Chrome
Up to 4.0.249.78
Microsoft
Windows
All versions

Timeline

No history available yet.