CVE-2009-0411
Last modified
CVE-2009-0411 is a vulnerability of currently unknown severity. Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | <= 1.0.154.43 | |
| Chrome | 0.2.152.1 | |
| Chrome | 0.2.153.1 | |
| Chrome | 0.3.154.0 | |
| Chrome | 0.3.154.3 | |
| Chrome | 0.4.154.18 | |
| Chrome | 0.4.154.22 | |
| Chrome | 0.4.154.31 | |
| Chrome | 0.4.154.33 | |
| Chrome | 1.0.154.36 | |
| Chrome | 1.0.154.39 | |
| Chrome | 1.0.154.42 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0411?
How severe is CVE-2009-0411?
How do I fix CVE-2009-0411?
Are you affected by CVE-2009-0411?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
