← Back

CVE-2012-2848

nvd nist
Published: Aug 6, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site.

Affected (27)

Products: Google: Chrome
1 product
Chrome
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Up to 21.0.1180.56
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Linux
Linux Kernel
All versions
Configuration B
26 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Google
Up to 21.0.1180.59
Version 21.0.1180.0
Version 21.0.1180.1
Version 21.0.1180.2
Version 21.0.1180.31
Version 21.0.1180.32
Version 21.0.1180.33
Version 21.0.1180.34
Version 21.0.1180.35
Version 21.0.1180.36
Version 21.0.1180.37
Version 21.0.1180.38
Version 21.0.1180.39
Version 21.0.1180.41
Version 21.0.1180.46
Version 21.0.1180.47
Version 21.0.1180.48
Version 21.0.1180.49
Version 21.0.1180.50
Version 21.0.1180.51
Version 21.0.1180.52
Version 21.0.1180.53
Version 21.0.1180.54
Version 21.0.1180.55
Version 21.0.1180.56
Version 21.0.1180.57
Running on/withPlatform Versions
Google
Frame
All versions
Microsoft
Windows
All versions

Related CWEs

Timeline

No history available yet.