CVE-2010-1767 - CVE House
Back to Database
Status published Medium CVE-2010-1767

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1767

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

chrome
Vulnerable Versions:
0, 1.0.154.53, 1.0.154.59, 1.0.154.64, 1.0.154.65, 2.0.169.0, 2.0.169.1, 2.0.170.0, 2.0.172.2, 2.0.172.8, 2.0.172.27, 2.0.172.28, 2.0.172.30, 2.0.172.33, 2.0.172.37, 2.0.172.38, 3.0.182.2, 3.0.195.2, 3.0.195.21, 3.0.195.24, 3.0.195.25, 3.0.195.27, 3.0.195.33, 3.0.195.36, 3.0.195.37, 3.0.195.38, 4.0.212.0, 4.0.212.1, 4.0.221.8, 4.0.222.0, 4.0.222.1, 4.0.222.5, 4.0.222.12, 4.0.223.0, 4.0.223.1, 4.0.223.2, 4.0.223.4, 4.0.223.5, 4.0.223.7, 4.0.223.8, 4.0.223.9, 4.0.224.0, 4.0.229.1, 4.0.235.0, 4.0.236.0, 4.0.237.0, 4.0.237.1, 4.0.239.0, 4.0.240.0, 4.0.241.0, 4.0.242.0, 4.0.243.0, 4.0.244.0, 4.0.245.0, 4.0.245.1, 4.0.246.0, 4.0.247.0, 4.0.248.0, 4.0.249.0, 4.0.249.1, 4.0.249.2, 4.0.249.3, 4.0.249.4, 4.0.249.5, 4.0.249.6, 4.0.249.7, 4.0.249.8, 4.0.249.9, 4.0.249.10, 4.0.249.11, 4.0.249.12, 4.0.249.14, 4.0.249.16, 4.0.249.17, 4.0.249.18, 4.0.249.19, 4.0.249.20, 4.0.249.21, 4.0.249.22, 4.0.249.23, 4.0.249.24, 4.0.249.25, 4.0.249.26, 4.0.249.27, 4.0.249.28, 4.0.249.29, 4.0.249.30, 4.0.249.31, 4.0.249.32, 4.0.249.33, 4.0.249.34, 4.0.249.35, 4.0.249.36, 4.0.249.37, 4.0.249.38, 4.0.249.39, 4.0.249.40, 4.0.249.41, 4.0.249.42, 4.0.249.43, 4.0.249.44, 4.0.249.45, 4.0.249.46, 4.0.249.47, 4.0.249.48, 4.0.249.49, 4.0.249.50, 4.0.249.51, 4.0.249.52, 4.0.249.53, 4.0.249.54, 4.0.249.55, 4.0.249.56, 4.0.249.57, 4.0.249.58, 4.0.249.59, 4.0.249.61, 4.0.249.62, 4.0.249.63, 4.0.249.64, 4.0.249.65, 4.0.249.66, 4.0.249.67, 4.0.249.68, 4.0.249.69, 4.0.249.70, 4.0.249.71, 4.0.249.72, 4.0.249.73, 4.0.249.74, 4.0.249.75, 4.0.249.76, 4.0.249.77, 4.0.249.78, 4.0.249.79, 4.0.249.80, 4.0.249.81, 4.0.249.82, 4.0.249.89, 4.0.250.0, 4.0.250.2, 4.0.251.0, 4.0.252.0, 4.0.254.0, 4.0.255.0, 4.0.256.0, 4.0.257.0, 4.0.258.0, 4.0.259.0, 4.0.260.0, 4.0.261.0, 4.0.262.0, 4.0.263.0, 4.0.264.0, 4.0.265.0, 4.0.266.0, 4.0.267.0, 4.0.268.0, 4.0.269.0, 4.0.271.0, 4.0.272.0, 4.0.275.0, 4.0.275.1, 4.0.276.0, 4.0.277.0, 4.0.278.0, 4.0.286.0, 4.0.287.0, 4.0.288.0, 4.0.288.1, 4.0.289.0, 4.0.290.0, 4.0.292.0, 4.0.294.0, 4.0.295.0, 4.0.296.0, 4.0.299.0, 4.0.300.0, 4.0.301.0, 4.0.302.0, 4.0.302.1, 4.0.302.2, 4.0.302.3, 4.0.303.0, 4.0.304.0, 4.0.305.0, 4.1.249.0, 4.1.249.1001, 4.1.249.1004, 4.1.249.1006, 4.1.249.1007, 4.1.249.1008, 4.1.249.1009, 4.1.249.1010, 4.1.249.1011, 4.1.249.1012, 4.1.249.1013, 4.1.249.1014, 4.1.249.1015, 4.1.249.1016, 4.1.249.1017, 4.1.249.1018, 4.1.249.1019, 4.1.249.1020, 4.1.249.1021, 4.1.249.1022, 4.1.249.1023, 4.1.249.1024, 4.1.249.1025, 4.1.249.1026, 4.1.249.1027, 4.1.249.1028, 4.1.249.1029, 4.1.249.1030, 4.1.249.1031, 4.1.249.1032, 4.1.249.1033, 4.1.249.1034, 4.1.249.1035, 4.1.249.1036, 4.1.249.1042, 4.1.249.1045, 4.1.249.1046, 4.1.249.1047, 4.1.249.1048, 4.1.249.1049, 4.1.249.1050, 4.1.249.1051, 4.1.249.1052, 4.1.249.1053, 4.1.249.1054, 4.1.249.1055, 4.1.249.1056, 4.1.249.1057

Timeline

Official Publish: September 24th, 2010
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.