CVE-2009-2068

Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
operaopera
5..10
operaopera
5.0
operaopera
5.0:beta_2
operaopera
5.0:beta_3
operaopera
5.0:beta_4
operaopera
5.0:beta_5
operaopera
5.0:beta_6
operaopera
5.0:beta_7
operaopera
5.0:beta_8
operaopera
5.1
operaopera
5.02
operaopera
5.2
operaopera
5.3
operaopera
5.4
operaopera
5.5
operaopera
5.6
operaopera
5.7
operaopera
5.8
operaopera
5.9
operaopera
5.10
operaopera
5.11
operaopera
5.12
operaopera
6.0
operaopera
6.0:beta_1
operaopera
6.0:beta_2
operaopera
6.0:beta_3
operaopera
6.1
operaopera
6.01
operaopera
6.02
operaopera
6.03
operaopera
6.04
operaopera
6.05
operaopera
6.06
operaopera
6.11
operaopera
6.12
operaopera
7.0
operaopera
7.0:beta_1
operaopera
7.0:beta_1v2
operaopera
7.0:beta_2
operaopera
7.01
operaopera
7.02
operaopera
7.03
operaopera
7.10
operaopera
7.11
operaopera
7.20
operaopera
7.20:beta7
operaopera
7.21
operaopera
7.22
operaopera
7.23
operaopera
7.30
operaopera
7.50
operaopera
7.50:beta_1
operaopera
7.51
operaopera
7.52
operaopera
7.54
operaopera
7.54:update_1
operaopera
7.55
operaopera
8.0
operaopera
8.0:beta_1
operaopera
8.0:beta_2
operaopera
8.01
operaopera
8.02
operaopera
8.51
operaopera
8.52
operaopera
8.53
operaopera
8.54
operaopera
9.0:beta_1
operaopera
9.01
operaopera
9.02
operaopera
9.10
operaopera
9.20
operaopera
9.21
operaopera
9.23
𝑥
= Vulnerable software versions