Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Chrome 信息泄露漏洞
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。 基于Windows、OS X及Linux平台的Google Chrome 36.0.1985.142及之前版本和基于Android平台的Google Chrome 36.0.1985.134及之前版本的Public Key Pinning(PKP)实现中存在安全漏洞,该漏洞源于程序没有正确验证SPDY连接的属性。远程攻击者可通过使用多个域名利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A