CVE-2011-2878

EUVD-2011-2852
Google Chrome before 14.0.835.202 does not properly restrict access to the window prototype, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
< 14.0.835.202
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
hardy
dne
lucid
Fixed 14.0.835.202~r103287-0ubuntu0.10.04.2
released
maverick
Fixed 14.0.835.202~r103287-0ubuntu0.10.10.1
released
natty
Fixed 14.0.835.202~r103287-0ubuntu0.11.04.1
released
oneiric
not-affected