← Back

CVE-2010-1236

nvd nist
Published: Apr 1, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \x00javascript:alert sequence.

Affected (225)

Products: Google: Chrome · Flock: Flock
1 product
Chrome
1 product
Flock
Configuration A
224 vulnerable
Vulnerable SoftwareAffected Versions
Google
Up to 4.1.249.1035
Version 0.1.38.1
Version 0.1.38.2
Version 0.1.38.4
Version 0.1.40.1
Version 0.1.42.2
Version 0.1.42.3
Version 1.0.154.53
Version 1.0.154.59
Version 1.0.154.64
Version 1.0.154.65
Version 2.0.169.0
Version 2.0.169.1
Version 2.0.170.0
Version 2.0.172.27
Version 2.0.172.28
Version 2.0.172.2
Version 2.0.172.30
Version 2.0.172.33
Version 2.0.172.37
Version 2.0.172.38
Version 2.0.172.8
Version 3.0.182.2
Version 3.0.190.2
Version 3.0.195.25
Version 3.0.195.27
Version 3.0.195.33
Version 3.0.195.36
Version 3.0.195.37
Version 3.0.195.38
Version 4.0.212.0
Version 4.0.212.1
Version 4.0.221.8
Version 4.0.222.0
Version 4.0.222.12
Version 4.0.222.1
Version 4.0.222.5
Version 4.0.223.0
Version 4.0.223.1
Version 4.0.223.2
Version 4.0.223.4
Version 4.0.223.5
Version 4.0.223.7
Version 4.0.223.8
Version 4.0.223.9
Version 4.0.224.0
Version 4.0.229.1
Version 4.0.235.0
Version 4.0.236.0
Version 4.0.237.0
Version 4.0.237.1
Version 4.0.239.0
Version 4.0.240.0
Version 4.0.241.0
Version 4.0.242.0
Version 4.0.243.0
Version 4.0.244.0
Version 4.0.245.0
Version 4.0.245.1
Version 4.0.246.0
Version 4.0.247.0
Version 4.0.248.0
Version 4.0.249.0
Version 4.0.249.10
Version 4.0.249.11
Version 4.0.249.12
Version 4.0.249.14
Version 4.0.249.16
Version 4.0.249.17
Version 4.0.249.18
Version 4.0.249.19
Version 4.0.249.1
Version 4.0.249.20
Version 4.0.249.21
Version 4.0.249.22
Version 4.0.249.23
Version 4.0.249.24
Version 4.0.249.25
Version 4.0.249.26
Version 4.0.249.27
Version 4.0.249.28
Version 4.0.249.29
Version 4.0.249.2
Version 4.0.249.30
Version 4.0.249.31
Version 4.0.249.32
Version 4.0.249.33
Version 4.0.249.34
Version 4.0.249.35
Version 4.0.249.36
Version 4.0.249.37
Version 4.0.249.38
Version 4.0.249.39
Version 4.0.249.3
Version 4.0.249.40
Version 4.0.249.41
Version 4.0.249.42
Version 4.0.249.43
Version 4.0.249.44
Version 4.0.249.45
Version 4.0.249.46
Version 4.0.249.47
Version 4.0.249.48
Version 4.0.249.49
Version 4.0.249.4
Version 4.0.249.50
Version 4.0.249.51
Version 4.0.249.52
Version 4.0.249.53
Version 4.0.249.54
Version 4.0.249.55
Version 4.0.249.56
Version 4.0.249.57
Version 4.0.249.58
Version 4.0.249.59
Version 4.0.249.5
Version 4.0.249.60
Version 4.0.249.61
Version 4.0.249.62
Version 4.0.249.63
Version 4.0.249.64
Version 4.0.249.65
Version 4.0.249.66
Version 4.0.249.67
Version 4.0.249.68
Version 4.0.249.69
Version 4.0.249.6
Version 4.0.249.70
Version 4.0.249.71
Version 4.0.249.72
Version 4.0.249.73
Version 4.0.249.74
Version 4.0.249.75
Version 4.0.249.76
Version 4.0.249.77
Version 4.0.249.78
Version 4.0.249.78 beta
Version 4.0.249.79
Version 4.0.249.7
Version 4.0.249.80
Version 4.0.249.81
Version 4.0.249.82
Version 4.0.249.89
Version 4.0.249.8
Version 4.0.249.9
Version 4.0.250.0
Version 4.0.250.2
Version 4.0.251.0
Version 4.0.252.0
Version 4.0.254.0
Version 4.0.255.0
Version 4.0.256.0
Version 4.0.257.0
Version 4.0.258.0
Version 4.0.259.0
Version 4.0.260.0
Version 4.0.261.0
Version 4.0.262.0
Version 4.0.263.0
Version 4.0.264.0
Version 4.0.265.0
Version 4.0.266.0
Version 4.0.267.0
Version 4.0.268.0
Version 4.0.269.0
Version 4.0.271.0
Version 4.0.272.0
Version 4.0.275.0
Version 4.0.275.1
Version 4.0.276.0
Version 4.0.277.0
Version 4.0.278.0
Version 4.0.286.0
Version 4.0.287.0
Version 4.0.288.0
Version 4.0.288.1
Version 4.0.289.0
Version 4.0.290.0
Version 4.0.292.0
Version 4.0.294.0
Version 4.0.295.0
Version 4.0.296.0
Version 4.0.299.0
Version 4.0.300.0
Version 4.0.301.0
Version 4.0.302.0
Version 4.0.302.1
Version 4.0.302.2
Version 4.0.302.3
Version 4.0.303.0
Version 4.0.304.0
Version 4.0.305.0
Version 4.1.249.0
Version 4.1.249.1001
Version 4.1.249.1004
Version 4.1.249.1006
Version 4.1.249.1007
Version 4.1.249.1008
Version 4.1.249.1009
Version 4.1.249.1010
Version 4.1.249.1011
Version 4.1.249.1012
Version 4.1.249.1013
Version 4.1.249.1014
Version 4.1.249.1015
Version 4.1.249.1016
Version 4.1.249.1017
Version 4.1.249.1018
Version 4.1.249.1019
Version 4.1.249.1020
Version 4.1.249.1021
Version 4.1.249.1022
Version 4.1.249.1023
Version 4.1.249.1024
Version 4.1.249.1025
Version 4.1.249.1026
Version 4.1.249.1027
Version 4.1.249.1028
Version 4.1.249.1029
Version 4.1.249.1030
Version 4.1.249.1031
Version 4.1.249.1032
Version 4.1.249.1033
Version 4.1.249.1034
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0.0.4094

References (20)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.