The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \x00javascript:alert sequence.
総合評価: CVE-2010-1236 は公開エクスプロイトあり(56.5/100)。CVSS 深刻度は中。悪用される可能性が高い(EPSS 0.62%、69 パーセンタイル) 根拠: 公開エクスプロイトが 1 件参照されています(Exploit-DB)。 推奨対応: 公開エクスプロイトが確認されています。影響範囲の確認、緩和策の適用、パッチ適用を優先してください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
| EDB-ID | ソース | 種別 | 公開 | リンク |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2025-09-12 | 0.51% | 0.62% | +0.11% |
| 2 | 2025-03-30 | 0.71% | 0.51% | -0.20% |
| 3 | 2025-03-29 | — | 0.71% | — |
EPSS の全履歴 (全 7 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2010-1236 medium priority: Ubuntu including 1 source packages (chromium-browser), 7 status rows across 7 suites (dapper, hardy, intrepid, jaunty, karmic, lucid, upstream): DNE 5, needs-triage 1, released 1. | https://ubuntu.com/security/CVE-2010-1236 |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| chrome | <= 4.1.249.1035 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
| chrome | 0.1.38.1 | cpe:2.3:a:google:chrome:0.1.38.1:*:*:*:*:*:*:* | |
| chrome | 0.1.38.2 | cpe:2.3:a:google:chrome:0.1.38.2:*:*:*:*:*:*:* | |
| chrome | 0.1.38.4 | cpe:2.3:a:google:chrome:0.1.38.4:*:*:*:*:*:*:* | |
| chrome | 0.1.40.1 | cpe:2.3:a:google:chrome:0.1.40.1:*:*:*:*:*:*:* | |
| chrome | 0.1.42.2 | cpe:2.3:a:google:chrome:0.1.42.2:*:*:*:*:*:*:* | |
| chrome | 0.1.42.3 | cpe:2.3:a:google:chrome:0.1.42.3:*:*:*:*:*:*:* | |
| chrome | 1.0.154.53 | cpe:2.3:a:google:chrome:1.0.154.53:*:*:*:*:*:*:* | |
| chrome | 1.0.154.59 | cpe:2.3:a:google:chrome:1.0.154.59:*:*:*:*:*:*:* | |
| chrome | 1.0.154.64 | cpe:2.3:a:google:chrome:1.0.154.64:*:*:*:*:*:*:* | |
| chrome | 1.0.154.65 | cpe:2.3:a:google:chrome:1.0.154.65:*:*:*:*:*:*:* | |
| chrome | 2.0.169.0 | cpe:2.3:a:google:chrome:2.0.169.0:*:*:*:*:*:*:* | |
| chrome | 2.0.169.1 | cpe:2.3:a:google:chrome:2.0.169.1:*:*:*:*:*:*:* | |
| chrome | 2.0.170.0 | cpe:2.3:a:google:chrome:2.0.170.0:*:*:*:*:*:*:* | |
| chrome | 2.0.172.2 | cpe:2.3:a:google:chrome:2.0.172.2:*:*:*:*:*:*:* | |
| chrome | 2.0.172.8 | cpe:2.3:a:google:chrome:2.0.172.8:*:*:*:*:*:*:* | |
| chrome | 2.0.172.27 | cpe:2.3:a:google:chrome:2.0.172.27:*:*:*:*:*:*:* | |
| chrome | 2.0.172.28 | cpe:2.3:a:google:chrome:2.0.172.28:*:*:*:*:*:*:* | |
| chrome | 2.0.172.30 | cpe:2.3:a:google:chrome:2.0.172.30:*:*:*:*:*:*:* | |
| chrome | 2.0.172.33 | cpe:2.3:a:google:chrome:2.0.172.33:*:*:*:*:*:*:* | |
| chrome | 2.0.172.37 | cpe:2.3:a:google:chrome:2.0.172.37:*:*:*:*:*:*:* | |
| chrome | 2.0.172.38 | cpe:2.3:a:google:chrome:2.0.172.38:*:*:*:*:*:*:* | |
| chrome | 3.0.182.2 | cpe:2.3:a:google:chrome:3.0.182.2:*:*:*:*:*:*:* | |
| chrome | 3.0.190.2 | cpe:2.3:a:google:chrome:3.0.190.2:*:*:*:*:*:*:* | |
| chrome | 3.0.195.25 | cpe:2.3:a:google:chrome:3.0.195.25:*:*:*:*:*:*:* | |
| chrome | 3.0.195.27 | cpe:2.3:a:google:chrome:3.0.195.27:*:*:*:*:*:*:* | |
| chrome | 3.0.195.33 | cpe:2.3:a:google:chrome:3.0.195.33:*:*:*:*:*:*:* | |
| chrome | 3.0.195.36 | cpe:2.3:a:google:chrome:3.0.195.36:*:*:*:*:*:*:* | |
| chrome | 3.0.195.37 | cpe:2.3:a:google:chrome:3.0.195.37:*:*:*:*:*:*:* | |
| chrome | 3.0.195.38 | cpe:2.3:a:google:chrome:3.0.195.38:*:*:*:*:*:*:* | |
| chrome | 4.0.212.0 | cpe:2.3:a:google:chrome:4.0.212.0:*:*:*:*:*:*:* | |
| chrome | 4.0.212.1 | cpe:2.3:a:google:chrome:4.0.212.1:*:*:*:*:*:*:* | |
| chrome | 4.0.221.8 | cpe:2.3:a:google:chrome:4.0.221.8:*:*:*:*:*:*:* | |
| chrome | 4.0.222.0 | cpe:2.3:a:google:chrome:4.0.222.0:*:*:*:*:*:*:* | |
| chrome | 4.0.222.1 | cpe:2.3:a:google:chrome:4.0.222.1:*:*:*:*:*:*:* | |
| chrome | 4.0.222.5 | cpe:2.3:a:google:chrome:4.0.222.5:*:*:*:*:*:*:* | |
| chrome | 4.0.222.12 | cpe:2.3:a:google:chrome:4.0.222.12:*:*:*:*:*:*:* | |
| chrome | 4.0.223.0 | cpe:2.3:a:google:chrome:4.0.223.0:*:*:*:*:*:*:* | |
| chrome | 4.0.223.1 | cpe:2.3:a:google:chrome:4.0.223.1:*:*:*:*:*:*:* | |
| chrome | 4.0.223.2 | cpe:2.3:a:google:chrome:4.0.223.2:*:*:*:*:*:*:* | |
| chrome | 4.0.223.4 | cpe:2.3:a:google:chrome:4.0.223.4:*:*:*:*:*:*:* | |
| chrome | 4.0.223.5 | cpe:2.3:a:google:chrome:4.0.223.5:*:*:*:*:*:*:* | |
| chrome | 4.0.223.7 | cpe:2.3:a:google:chrome:4.0.223.7:*:*:*:*:*:*:* | |
| chrome | 4.0.223.8 | cpe:2.3:a:google:chrome:4.0.223.8:*:*:*:*:*:*:* | |
| chrome | 4.0.223.9 | cpe:2.3:a:google:chrome:4.0.223.9:*:*:*:*:*:*:* | |
| chrome | 4.0.224.0 | cpe:2.3:a:google:chrome:4.0.224.0:*:*:*:*:*:*:* | |
| chrome | 4.0.229.1 | cpe:2.3:a:google:chrome:4.0.229.1:*:*:*:*:*:*:* | |
| chrome | 4.0.235.0 | cpe:2.3:a:google:chrome:4.0.235.0:*:*:*:*:*:*:* | |
| chrome | 4.0.236.0 | cpe:2.3:a:google:chrome:4.0.236.0:*:*:*:*:*:*:* | |
| chrome | 4.0.237.0 | cpe:2.3:a:google:chrome:4.0.237.0:*:*:*:*:*:*:* | |
| chrome | 4.0.237.1 | cpe:2.3:a:google:chrome:4.0.237.1:*:*:*:*:*:*:* | |
| chrome | 4.0.239.0 | cpe:2.3:a:google:chrome:4.0.239.0:*:*:*:*:*:*:* | |
| chrome | 4.0.240.0 | cpe:2.3:a:google:chrome:4.0.240.0:*:*:*:*:*:*:* | |
| chrome | 4.0.241.0 | cpe:2.3:a:google:chrome:4.0.241.0:*:*:*:*:*:*:* | |
| chrome | 4.0.242.0 | cpe:2.3:a:google:chrome:4.0.242.0:*:*:*:*:*:*:* | |
| chrome | 4.0.243.0 | cpe:2.3:a:google:chrome:4.0.243.0:*:*:*:*:*:*:* | |
| chrome | 4.0.244.0 | cpe:2.3:a:google:chrome:4.0.244.0:*:*:*:*:*:*:* | |
| chrome | 4.0.245.0 | cpe:2.3:a:google:chrome:4.0.245.0:*:*:*:*:*:*:* | |
| chrome | 4.0.245.1 | cpe:2.3:a:google:chrome:4.0.245.1:*:*:*:*:*:*:* | |
| chrome | 4.0.246.0 | cpe:2.3:a:google:chrome:4.0.246.0:*:*:*:*:*:*:* | |
| chrome | 4.0.247.0 | cpe:2.3:a:google:chrome:4.0.247.0:*:*:*:*:*:*:* | |
| chrome | 4.0.248.0 | cpe:2.3:a:google:chrome:4.0.248.0:*:*:*:*:*:*:* | |
| chrome | 4.0.249.0 | cpe:2.3:a:google:chrome:4.0.249.0:*:*:*:*:*:*:* | |
| chrome | 4.0.249.1 | cpe:2.3:a:google:chrome:4.0.249.1:*:*:*:*:*:*:* | |
| chrome | 4.0.249.2 | cpe:2.3:a:google:chrome:4.0.249.2:*:*:*:*:*:*:* | |
| chrome | 4.0.249.3 | cpe:2.3:a:google:chrome:4.0.249.3:*:*:*:*:*:*:* | |
| chrome | 4.0.249.4 | cpe:2.3:a:google:chrome:4.0.249.4:*:*:*:*:*:*:* | |
| chrome | 4.0.249.5 | cpe:2.3:a:google:chrome:4.0.249.5:*:*:*:*:*:*:* | |
| chrome | 4.0.249.6 | cpe:2.3:a:google:chrome:4.0.249.6:*:*:*:*:*:*:* | |
| chrome | 4.0.249.7 | cpe:2.3:a:google:chrome:4.0.249.7:*:*:*:*:*:*:* | |
| chrome | 4.0.249.8 | cpe:2.3:a:google:chrome:4.0.249.8:*:*:*:*:*:*:* | |
| chrome | 4.0.249.9 | cpe:2.3:a:google:chrome:4.0.249.9:*:*:*:*:*:*:* | |
| chrome | 4.0.249.10 | cpe:2.3:a:google:chrome:4.0.249.10:*:*:*:*:*:*:* | |
| chrome | 4.0.249.11 | cpe:2.3:a:google:chrome:4.0.249.11:*:*:*:*:*:*:* | |
| chrome | 4.0.249.12 | cpe:2.3:a:google:chrome:4.0.249.12:*:*:*:*:*:*:* | |
| chrome | 4.0.249.14 | cpe:2.3:a:google:chrome:4.0.249.14:*:*:*:*:*:*:* | |
| chrome | 4.0.249.16 | cpe:2.3:a:google:chrome:4.0.249.16:*:*:*:*:*:*:* | |
| chrome | 4.0.249.17 | cpe:2.3:a:google:chrome:4.0.249.17:*:*:*:*:*:*:* | |
| chrome | 4.0.249.18 | cpe:2.3:a:google:chrome:4.0.249.18:*:*:*:*:*:*:* | |
| chrome | 4.0.249.19 | cpe:2.3:a:google:chrome:4.0.249.19:*:*:*:*:*:*:* |