Unrated severityNVD Advisory· Published Feb 18, 2010· Updated Apr 29, 2026
CVE-2010-0643
CVE-2010-0643
Description
Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.
Affected products
47cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*+ 46 more
- cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*range: <=4.0.249.78
- cpe:2.3:a:google:chrome:0.2.149.27:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.2.149.29:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.2.149.30:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.2.152.1:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.2.153.1:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.3.154.0:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.3.154.3:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.4.154.18:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.4.154.22:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.4.154.31:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:0.4.154.33:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.36:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.39:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.42:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.43:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.46:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.48:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.52:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.53:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.59:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:1.0.154.65:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.156.1:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.157.0:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.157.2:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.158.0:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.159.0:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.169.0:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.169.1:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.170.0:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.2:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.27:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.28:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.30:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.31:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.33:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.37:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.38:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:2.0.172.8:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.182.2:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.190.2:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.193.2:beta:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.195.21:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.195.24:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.195.32:*:*:*:*:*:*:*
- cpe:2.3:a:google:chrome:3.0.195.33:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- googlechromereleases.blogspot.com/2010/02/stable-channel-update.htmlnvdPatch
- secunia.com/advisories/38545nvdVendor Advisory
- sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugsnvdVendor Advisory
- www.vupen.com/english/advisories/2010/0361nvdVendor Advisory
- code.google.com/p/chromium/issues/detailnvd
- securitytracker.com/idnvd
- www.osvdb.org/62315nvd
- www.securityfocus.com/bid/38177nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/56212nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14500nvd
News mentions
0No linked articles in our index yet.