CVE-2010-1236
Summary
| CVE | CVE-2010-1236 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-01 22:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \x00javascript:alert sequence. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Flock | Flock | 3.0.0.4094 | All | All | All |
| Application | Chrome | 0.1.38.1 | All | All | All | |
| Application | Chrome | 0.1.38.2 | All | All | All | |
| Application | Chrome | 0.1.38.4 | All | All | All | |
| Application | Chrome | 0.1.40.1 | All | All | All | |
| Application | Chrome | 0.1.42.2 | All | All | All | |
| Application | Chrome | 0.1.42.3 | All | All | All | |
| Application | Chrome | 1.0.154.53 | All | All | All | |
| Application | Chrome | 1.0.154.59 | All | All | All | |
| Application | Chrome | 1.0.154.64 | All | All | All | |
| Application | Chrome | 1.0.154.65 | All | All | All | |
| Application | Chrome | 2.0.169.0 | All | All | All | |
| Application | Chrome | 2.0.169.1 | All | All | All | |
| Application | Chrome | 2.0.170.0 | All | All | All | |
| Application | Chrome | 2.0.172.2 | All | All | All | |
| Application | Chrome | 2.0.172.27 | All | All | All | |
| Application | Chrome | 2.0.172.28 | All | All | All | |
| Application | Chrome | 2.0.172.30 | All | All | All | |
| Application | Chrome | 2.0.172.33 | All | All | All | |
| Application | Chrome | 2.0.172.37 | All | All | All | |
| Application | Chrome | 2.0.172.38 | All | All | All | |
| Application | Chrome | 2.0.172.8 | All | All | All | |
| Application | Chrome | 3.0.182.2 | All | All | All | |
| Application | Chrome | 3.0.190.2 | All | All | All | |
| Application | Chrome | 3.0.195.25 | All | All | All | |
| Application | Chrome | 3.0.195.27 | All | All | All | |
| Application | Chrome | 3.0.195.33 | All | All | All | |
| Application | Chrome | 3.0.195.36 | All | All | All | |
| Application | Chrome | 3.0.195.37 | All | All | All | |
| Application | Chrome | 3.0.195.38 | All | All | All | |
| Application | Chrome | 4.0.212.0 | All | All | All | |
| Application | Chrome | 4.0.212.1 | All | All | All | |
| Application | Chrome | 4.0.221.8 | All | All | All | |
| Application | Chrome | 4.0.222.0 | All | All | All | |
| Application | Chrome | 4.0.222.1 | All | All | All | |
| Application | Chrome | 4.0.222.12 | All | All | All | |
| Application | Chrome | 4.0.222.5 | All | All | All | |
| Application | Chrome | 4.0.223.0 | All | All | All | |
| Application | Chrome | 4.0.223.1 | All | All | All | |
| Application | Chrome | 4.0.223.2 | All | All | All | |
| Application | Chrome | 4.0.223.4 | All | All | All | |
| Application | Chrome | 4.0.223.5 | All | All | All | |
| Application | Chrome | 4.0.223.7 | All | All | All | |
| Application | Chrome | 4.0.223.8 | All | All | All | |
| Application | Chrome | 4.0.223.9 | All | All | All | |
| Application | Chrome | 4.0.224.0 | All | All | All | |
| Application | Chrome | 4.0.229.1 | All | All | All | |
| Application | Chrome | 4.0.235.0 | All | All | All | |
| Application | Chrome | 4.0.236.0 | All | All | All | |
| Application | Chrome | 4.0.237.0 | All | All | All | |
| Application | Chrome | 4.0.237.1 | All | All | All | |
| Application | Chrome | 4.0.239.0 | All | All | All | |
| Application | Chrome | 4.0.240.0 | All | All | All | |
| Application | Chrome | 4.0.241.0 | All | All | All | |
| Application | Chrome | 4.0.242.0 | All | All | All | |
| Application | Chrome | 4.0.243.0 | All | All | All | |
| Application | Chrome | 4.0.244.0 | All | All | All | |
| Application | Chrome | 4.0.245.0 | All | All | All | |
| Application | Chrome | 4.0.245.1 | All | All | All | |
| Application | Chrome | 4.0.246.0 | All | All | All | |
| Application | Chrome | 4.0.247.0 | All | All | All | |
| Application | Chrome | 4.0.248.0 | All | All | All | |
| Application | Chrome | 4.0.249.0 | All | All | All | |
| Application | Chrome | 4.0.249.1 | All | All | All | |
| Application | Chrome | 4.0.249.10 | All | All | All | |
| Application | Chrome | 4.0.249.11 | All | All | All | |
| Application | Chrome | 4.0.249.12 | All | All | All | |
| Application | Chrome | 4.0.249.14 | All | All | All | |
| Application | Chrome | 4.0.249.16 | All | All | All | |
| Application | Chrome | 4.0.249.17 | All | All | All | |
| Application | Chrome | 4.0.249.18 | All | All | All | |
| Application | Chrome | 4.0.249.19 | All | All | All | |
| Application | Chrome | 4.0.249.2 | All | All | All | |
| Application | Chrome | 4.0.249.20 | All | All | All | |
| Application | Chrome | 4.0.249.21 | All | All | All | |
| Application | Chrome | 4.0.249.22 | All | All | All | |
| Application | Chrome | 4.0.249.23 | All | All | All | |
| Application | Chrome | 4.0.249.24 | All | All | All | |
| Application | Chrome | 4.0.249.25 | All | All | All | |
| Application | Chrome | 4.0.249.26 | All | All | All | |
| Application | Chrome | 4.0.249.27 | All | All | All | |
| Application | Chrome | 4.0.249.28 | All | All | All | |
| Application | Chrome | 4.0.249.29 | All | All | All | |
| Application | Chrome | 4.0.249.3 | All | All | All | |
| Application | Chrome | 4.0.249.30 | All | All | All | |
| Application | Chrome | 4.0.249.31 | All | All | All | |
| Application | Chrome | 4.0.249.32 | All | All | All | |
| Application | Chrome | 4.0.249.33 | All | All | All | |
| Application | Chrome | 4.0.249.34 | All | All | All | |
| Application | Chrome | 4.0.249.35 | All | All | All | |
| Application | Chrome | 4.0.249.36 | All | All | All | |
| Application | Chrome | 4.0.249.37 | All | All | All | |
| Application | Chrome | 4.0.249.38 | All | All | All | |
| Application | Chrome | 4.0.249.39 | All | All | All | |
| Application | Chrome | 4.0.249.4 | All | All | All | |
| Application | Chrome | 4.0.249.40 | All | All | All | |
| Application | Chrome | 4.0.249.41 | All | All | All | |
| Application | Chrome | 4.0.249.42 | All | All | All | |
| Application | Chrome | 4.0.249.43 | All | All | All | |
| Application | Chrome | 4.0.249.44 | All | All | All | |
| Application | Chrome | 4.0.249.45 | All | All | All | |
| Application | Chrome | 4.0.249.46 | All | All | All | |
| Application | Chrome | 4.0.249.47 | All | All | All | |
| Application | Chrome | 4.0.249.48 | All | All | All | |
| Application | Chrome | 4.0.249.49 | All | All | All | |
| Application | Chrome | 4.0.249.5 | All | All | All | |
| Application | Chrome | 4.0.249.50 | All | All | All | |
| Application | Chrome | 4.0.249.51 | All | All | All | |
| Application | Chrome | 4.0.249.52 | All | All | All | |
| Application | Chrome | 4.0.249.53 | All | All | All | |
| Application | Chrome | 4.0.249.54 | All | All | All | |
| Application | Chrome | 4.0.249.55 | All | All | All | |
| Application | Chrome | 4.0.249.56 | All | All | All | |
| Application | Chrome | 4.0.249.57 | All | All | All | |
| Application | Chrome | 4.0.249.58 | All | All | All | |
| Application | Chrome | 4.0.249.59 | All | All | All | |
| Application | Chrome | 4.0.249.6 | All | All | All | |
| Application | Chrome | 4.0.249.60 | All | All | All | |
| Application | Chrome | 4.0.249.61 | All | All | All | |
| Application | Chrome | 4.0.249.62 | All | All | All | |
| Application | Chrome | 4.0.249.63 | All | All | All | |
| Application | Chrome | 4.0.249.64 | All | All | All | |
| Application | Chrome | 4.0.249.65 | All | All | All | |
| Application | Chrome | 4.0.249.66 | All | All | All | |
| Application | Chrome | 4.0.249.67 | All | All | All | |
| Application | Chrome | 4.0.249.68 | All | All | All | |
| Application | Chrome | 4.0.249.69 | All | All | All | |
| Application | Chrome | 4.0.249.7 | All | All | All | |
| Application | Chrome | 4.0.249.70 | All | All | All | |
| Application | Chrome | 4.0.249.71 | All | All | All | |
| Application | Chrome | 4.0.249.72 | All | All | All | |
| Application | Chrome | 4.0.249.73 | All | All | All | |
| Application | Chrome | 4.0.249.74 | All | All | All | |
| Application | Chrome | 4.0.249.75 | All | All | All | |
| Application | Chrome | 4.0.249.76 | All | All | All | |
| Application | Chrome | 4.0.249.77 | All | All | All | |
| Application | Chrome | 4.0.249.78 | All | All | All | |
| Application | Chrome | 4.0.249.78 | beta | All | All | |
| Application | Chrome | 4.0.249.79 | All | All | All | |
| Application | Chrome | 4.0.249.8 | All | All | All | |
| Application | Chrome | 4.0.249.80 | All | All | All | |
| Application | Chrome | 4.0.249.81 | All | All | All | |
| Application | Chrome | 4.0.249.82 | All | All | All | |
| Application | Chrome | 4.0.249.89 | All | All | All | |
| Application | Chrome | 4.0.249.9 | All | All | All | |
| Application | Chrome | 4.0.250.0 | All | All | All | |
| Application | Chrome | 4.0.250.2 | All | All | All | |
| Application | Chrome | 4.0.251.0 | All | All | All | |
| Application | Chrome | 4.0.252.0 | All | All | All | |
| Application | Chrome | 4.0.254.0 | All | All | All | |
| Application | Chrome | 4.0.255.0 | All | All | All | |
| Application | Chrome | 4.0.256.0 | All | All | All | |
| Application | Chrome | 4.0.257.0 | All | All | All | |
| Application | Chrome | 4.0.258.0 | All | All | All | |
| Application | Chrome | 4.0.259.0 | All | All | All | |
| Application | Chrome | 4.0.260.0 | All | All | All | |
| Application | Chrome | 4.0.261.0 | All | All | All | |
| Application | Chrome | 4.0.262.0 | All | All | All | |
| Application | Chrome | 4.0.263.0 | All | All | All | |
| Application | Chrome | 4.0.264.0 | All | All | All | |
| Application | Chrome | 4.0.265.0 | All | All | All | |
| Application | Chrome | 4.0.266.0 | All | All | All | |
| Application | Chrome | 4.0.267.0 | All | All | All | |
| Application | Chrome | 4.0.268.0 | All | All | All | |
| Application | Chrome | 4.0.269.0 | All | All | All | |
| Application | Chrome | 4.0.271.0 | All | All | All | |
| Application | Chrome | 4.0.272.0 | All | All | All | |
| Application | Chrome | 4.0.275.0 | All | All | All | |
| Application | Chrome | 4.0.275.1 | All | All | All | |
| Application | Chrome | 4.0.276.0 | All | All | All | |
| Application | Chrome | 4.0.277.0 | All | All | All | |
| Application | Chrome | 4.0.278.0 | All | All | All | |
| Application | Chrome | 4.0.286.0 | All | All | All | |
| Application | Chrome | 4.0.287.0 | All | All | All | |
| Application | Chrome | 4.0.288.0 | All | All | All | |
| Application | Chrome | 4.0.288.1 | All | All | All | |
| Application | Chrome | 4.0.289.0 | All | All | All | |
| Application | Chrome | 4.0.290.0 | All | All | All | |
| Application | Chrome | 4.0.292.0 | All | All | All | |
| Application | Chrome | 4.0.294.0 | All | All | All | |
| Application | Chrome | 4.0.295.0 | All | All | All | |
| Application | Chrome | 4.0.296.0 | All | All | All | |
| Application | Chrome | 4.0.299.0 | All | All | All | |
| Application | Chrome | 4.0.300.0 | All | All | All | |
| Application | Chrome | 4.0.301.0 | All | All | All | |
| Application | Chrome | 4.0.302.0 | All | All | All | |
| Application | Chrome | 4.0.302.1 | All | All | All | |
| Application | Chrome | 4.0.302.2 | All | All | All | |
| Application | Chrome | 4.0.302.3 | All | All | All | |
| Application | Chrome | 4.0.303.0 | All | All | All | |
| Application | Chrome | 4.0.304.0 | All | All | All | |
| Application | Chrome | 4.0.305.0 | All | All | All | |
| Application | Chrome | 4.1.249.0 | All | All | All | |
| Application | Chrome | 4.1.249.1001 | All | All | All | |
| Application | Chrome | 4.1.249.1004 | All | All | All | |
| Application | Chrome | 4.1.249.1006 | All | All | All | |
| Application | Chrome | 4.1.249.1007 | All | All | All | |
| Application | Chrome | 4.1.249.1008 | All | All | All | |
| Application | Chrome | 4.1.249.1009 | All | All | All | |
| Application | Chrome | 4.1.249.1010 | All | All | All | |
| Application | Chrome | 4.1.249.1011 | All | All | All | |
| Application | Chrome | 4.1.249.1012 | All | All | All | |
| Application | Chrome | 4.1.249.1013 | All | All | All | |
| Application | Chrome | 4.1.249.1014 | All | All | All | |
| Application | Chrome | 4.1.249.1015 | All | All | All | |
| Application | Chrome | 4.1.249.1016 | All | All | All | |
| Application | Chrome | 4.1.249.1017 | All | All | All | |
| Application | Chrome | 4.1.249.1018 | All | All | All | |
| Application | Chrome | 4.1.249.1019 | All | All | All | |
| Application | Chrome | 4.1.249.1020 | All | All | All | |
| Application | Chrome | 4.1.249.1021 | All | All | All | |
| Application | Chrome | 4.1.249.1022 | All | All | All | |
| Application | Chrome | 4.1.249.1023 | All | All | All | |
| Application | Chrome | 4.1.249.1024 | All | All | All | |
| Application | Chrome | 4.1.249.1025 | All | All | All | |
| Application | Chrome | 4.1.249.1026 | All | All | All | |
| Application | Chrome | 4.1.249.1027 | All | All | All | |
| Application | Chrome | 4.1.249.1028 | All | All | All | |
| Application | Chrome | 4.1.249.1029 | All | All | All | |
| Application | Chrome | 4.1.249.1030 | All | All | All | |
| Application | Chrome | 4.1.249.1031 | All | All | All | |
| Application | Chrome | 4.1.249.1032 | All | All | All | |
| Application | Chrome | 4.1.249.1033 | All | All | All | |
| Application | Chrome | 4.1.249.1034 | All | All | All | |
| Application | Chrome | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| SUSE update for Multiple Packages - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [chrome] Revision 41244 | af854a3a-2127-422b-91ae-364da2661108 | src.chromium.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugs.webkit.org | |
| Flock – A Secure Team Communication App | af854a3a-2127-422b-91ae-364da2661108 | flock.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:002 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Issue 37383 - chromium - javascript: url with a leading NULL byte can bypass cross origin protection. - An open-source browser project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | Exploit |
| Issue 858001: Merge WebKit r55822:... - Code Review | af854a3a-2127-422b-91ae-364da2661108 | codereview.chromium.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.