Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-7294

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.0%
CVSS Severity
CVSS v2 Score 5.8
References
Products affected by CVE-2008-7294
  • Google » Chrome » Version: N/A
    cpe:2.3:a:google:chrome:-
  • Google » Chrome » Version: 0.1.38.1
    cpe:2.3:a:google:chrome:0.1.38.1
  • Google » Chrome » Version: 0.1.38.2
    cpe:2.3:a:google:chrome:0.1.38.2
  • Google » Chrome » Version: 0.1.38.4
    cpe:2.3:a:google:chrome:0.1.38.4
  • Google » Chrome » Version: 0.1.40.1
    cpe:2.3:a:google:chrome:0.1.40.1
  • Google » Chrome » Version: 0.1.42.2
    cpe:2.3:a:google:chrome:0.1.42.2
  • Google » Chrome » Version: 0.1.42.3
    cpe:2.3:a:google:chrome:0.1.42.3
  • Google » Chrome » Version: 0.2.149.27
    cpe:2.3:a:google:chrome:0.2.149.27
  • Google » Chrome » Version: 0.2.149.29
    cpe:2.3:a:google:chrome:0.2.149.29
  • Google » Chrome » Version: 0.2.149.30
    cpe:2.3:a:google:chrome:0.2.149.30
  • Google » Chrome » Version: 0.2.152.1
    cpe:2.3:a:google:chrome:0.2.152.1
  • Google » Chrome » Version: 0.2.153.1
    cpe:2.3:a:google:chrome:0.2.153.1
  • Google » Chrome » Version: 0.3.154.0
    cpe:2.3:a:google:chrome:0.3.154.0
  • Google » Chrome » Version: 0.3.154.3
    cpe:2.3:a:google:chrome:0.3.154.3
  • Google » Chrome » Version: 0.4.154.18
    cpe:2.3:a:google:chrome:0.4.154.18
  • Google » Chrome » Version: 0.4.154.22
    cpe:2.3:a:google:chrome:0.4.154.22
  • Google » Chrome » Version: 0.4.154.31
    cpe:2.3:a:google:chrome:0.4.154.31
  • Google » Chrome » Version: 0.4.154.33
    cpe:2.3:a:google:chrome:0.4.154.33
  • Google » Chrome » Version: 1.0.154.36
    cpe:2.3:a:google:chrome:1.0.154.36
  • Google » Chrome » Version: 1.0.154.39
    cpe:2.3:a:google:chrome:1.0.154.39
  • Google » Chrome » Version: 1.0.154.42
    cpe:2.3:a:google:chrome:1.0.154.42
  • Google » Chrome » Version: 1.0.154.43
    cpe:2.3:a:google:chrome:1.0.154.43
  • Google » Chrome » Version: 1.0.154.46
    cpe:2.3:a:google:chrome:1.0.154.46
  • Google » Chrome » Version: 1.0.154.48
    cpe:2.3:a:google:chrome:1.0.154.48
  • Google » Chrome » Version: 1.0.154.52
    cpe:2.3:a:google:chrome:1.0.154.52
  • Google » Chrome » Version: 1.0.154.53
    cpe:2.3:a:google:chrome:1.0.154.53
  • Google » Chrome » Version: 1.0.154.59
    cpe:2.3:a:google:chrome:1.0.154.59
  • Google » Chrome » Version: 1.0.154.64
    cpe:2.3:a:google:chrome:1.0.154.64
  • Google » Chrome » Version: 1.0.154.65
    cpe:2.3:a:google:chrome:1.0.154.65
  • Google » Chrome » Version: 2.0.156.1
    cpe:2.3:a:google:chrome:2.0.156.1
  • Google » Chrome » Version: 2.0.157.0
    cpe:2.3:a:google:chrome:2.0.157.0
  • Google » Chrome » Version: 2.0.157.2
    cpe:2.3:a:google:chrome:2.0.157.2
  • Google » Chrome » Version: 2.0.158.0
    cpe:2.3:a:google:chrome:2.0.158.0
  • Google » Chrome » Version: 2.0.159.0
    cpe:2.3:a:google:chrome:2.0.159.0
  • Google » Chrome » Version: 2.0.169.0
    cpe:2.3:a:google:chrome:2.0.169.0
  • Google » Chrome » Version: 2.0.169.1
    cpe:2.3:a:google:chrome:2.0.169.1
  • Google » Chrome » Version: 2.0.170.0
    cpe:2.3:a:google:chrome:2.0.170.0
  • Google » Chrome » Version: 2.0.172
    cpe:2.3:a:google:chrome:2.0.172
  • Google » Chrome » Version: 2.0.172.2
    cpe:2.3:a:google:chrome:2.0.172.2
  • Google » Chrome » Version: 2.0.172.27
    cpe:2.3:a:google:chrome:2.0.172.27
  • Google » Chrome » Version: 2.0.172.28
    cpe:2.3:a:google:chrome:2.0.172.28
  • Google » Chrome » Version: 2.0.172.30
    cpe:2.3:a:google:chrome:2.0.172.30
  • Google » Chrome » Version: 2.0.172.31
    cpe:2.3:a:google:chrome:2.0.172.31
  • Google » Chrome » Version: 2.0.172.33
    cpe:2.3:a:google:chrome:2.0.172.33
  • Google » Chrome » Version: 2.0.172.37
    cpe:2.3:a:google:chrome:2.0.172.37
  • Google » Chrome » Version: 2.0.172.38
    cpe:2.3:a:google:chrome:2.0.172.38
  • Google » Chrome » Version: 2.0.172.43
    cpe:2.3:a:google:chrome:2.0.172.43
  • Google » Chrome » Version: 2.0.172.8
    cpe:2.3:a:google:chrome:2.0.172.8
  • Google » Chrome » Version: 3.0
    cpe:2.3:a:google:chrome:3.0
  • Google » Chrome » Version: 3.0.182.2
    cpe:2.3:a:google:chrome:3.0.182.2
  • Google » Chrome » Version: 3.0.190.2
    cpe:2.3:a:google:chrome:3.0.190.2
  • Google » Chrome » Version: 3.0.193.2
    cpe:2.3:a:google:chrome:3.0.193.2
  • Google » Chrome » Version: 3.0.195.2
    cpe:2.3:a:google:chrome:3.0.195.2
  • Google » Chrome » Version: 3.0.195.21
    cpe:2.3:a:google:chrome:3.0.195.21
  • Google » Chrome » Version: 3.0.195.24
    cpe:2.3:a:google:chrome:3.0.195.24
  • Google » Chrome » Version: 3.0.195.25
    cpe:2.3:a:google:chrome:3.0.195.25
  • Google » Chrome » Version: 3.0.195.27
    cpe:2.3:a:google:chrome:3.0.195.27
  • Google » Chrome » Version: 3.0.195.32
    cpe:2.3:a:google:chrome:3.0.195.32
  • Google » Chrome » Version: 3.0.195.33
    cpe:2.3:a:google:chrome:3.0.195.33
  • Google » Chrome » Version: 3.0.195.36
    cpe:2.3:a:google:chrome:3.0.195.36
  • Google » Chrome » Version: 3.0.195.37
    cpe:2.3:a:google:chrome:3.0.195.37
  • Google » Chrome » Version: 3.0.195.38
    cpe:2.3:a:google:chrome:3.0.195.38


Contact Us

Shodan ® - All rights reserved