Page 10 of 53 results (0.006 seconds)

CVSS: 10.0EPSS: 3%CPEs: 2EXPL: 1

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch in video frame sizes, which allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via unknown vectors. Google Chrome antes de v8.0.552.237 y Chrome OS antes de v8.0.552.344 no controla correctamente una discordancia en los tamaños de fotograma de vídeo, lo que permite a atacantes remotos provocar una denegación de servicio (por acceso a memoria incorrecto) o posiblemente tener un impacto no especificado a través de vectores desconocidos. • http://code.google.com/p/chromium/issues/detail?id=67303 http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.html http://osvdb.org/70460 http://secunia.com/advisories/42951 http://www.securityfocus.com/bid/45788 http://www.srware.net/forum/viewtopic.php?f=18&t=2054 https://exchange.xforce.ibmcloud.com/vulnerabilities/64668 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14390 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 0%CPEs: 7EXPL: 1

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue. Múltiples desbordamientos de búfer en el decodificador Vorbis en Google Chrome antes de v8.0.552.237 y Chrome OS antes de v8.0.552.344 permiten a atacantes remotos provocar una denegación de servicio o posiblemente tener un impacto no especificado a través de vectores desconocidos. • http://article.gmane.org/gmane.comp.video.ffmpeg.devel/122703 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610550 http://code.google.com/p/chromium/issues/detail?id=68115 http://codereview.chromium.org/5964011 http://codereview.chromium.org/6069005 http://ffmpeg.mplayerhq.hu http://git.ffmpeg.org/?p=ffmpeg.git%3Ba=commit%3Bh=13184036a6b1b1d4b61c91118c0896e9ad4634c3 http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.html http://osvdb.org/70463 http://roundup.ffmpeg. • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 4.3EPSS: 1%CPEs: 4EXPL: 0

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document. Google Chrome antes de v8.0.552.237 y Chrome OS antes de v8.0.552.344 no realiza correctamente la conversión de una variable no especificada durante la manipulación de los enlaces HTML, lo que permite a atacantes remotos provocar una denegación de servicio o posiblemente tener un impacto no especificado a través de un documento HTML. • http://code.google.com/p/chromium/issues/detail?id=68178 http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.html http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html http://osvdb.org/70465 http://secunia.com/advisories/42951 http://www.debian.org/security/2011/dsa-2188 http://www.securityfocus.com/bid/45788 http://www.srware.net/forum/viewtopic.php?f=18&t=2054 https://exchange.xforce.ibmcloud.com/vulnerabilities/64673 https://oval.cisec • CWE-704: Incorrect Type Conversion or Cast •

CVSS: 7.5EPSS: 1%CPEs: 3EXPL: 0

The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a denial of service or possibly have unspecified other impact, via invalid pickle data. La función Pickle::Pickle en base/pickle.cc de Google Chrome anterior a v8.0.552.224 y Chrome OS anterior a v8.0.552.343 en plataformas Linux de 64-bit no realizar correctamente la aritmética de punteros, lo cual permite a los atacantes remotos evitar la validación de mensajes deserialización, y causar una denegación de servicio o posiblemente otro impacto no especificado, a través de datos no válidos. • http://code.google.com/p/chromium/issues/detail?id=56449 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.html http://secunia.com/advisories/42648 http://src.chromium.org/viewvc/chrome?view=rev&revision=68033 http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml http://www.securityfocus.com/bid/45390 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14141 • CWE-502: Deserialization of Untrusted Data •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 1

The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted extension. La función ThemeInstalledInfoBarDelegate::Observe en browser/extensions/theme_installed_infobar_delegate.cc en Google Chrome anterior v8.0.552.224 y Chrome OS anterior v8.0.552.343 no maneja adecuadamente la cuenta de iteracción incorrecta por extensión, lo que permite a usuarios asistidos remotamente causar una denegación de servicio (caída aplicación) a través de una extensión manipulada. • http://code.google.com/p/chromium/issues/detail?id=60761 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.html http://secunia.com/advisories/42648 http://src.chromium.org/viewvc/chrome?view=rev&revision=68112 http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml http://www.securityfocus.com/bid/45390 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14427 • CWE-20: Improper Input Validation •