CVE-2011-2878

Google Chrome before 14.0.835.202 does not properly restrict access to the window prototype, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
< 14.0.835.202
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
hardy
dne
lucid
Fixed 14.0.835.202~r103287-0ubuntu0.10.04.2
released
maverick
Fixed 14.0.835.202~r103287-0ubuntu0.10.10.1
released
natty
Fixed 14.0.835.202~r103287-0ubuntu0.11.04.1
released
oneiric
not-affected