CVE-2012-2883
https://notcve.org/view.php?id=CVE-2012-2883
26 Sep 2012 — Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2874. Skia usado en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores que causan una operación que provoca una escritura fuera de rango. Vulnerabilidad distinta de CVE-... • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-2874
https://notcve.org/view.php?id=CVE-2012-2874
26 Sep 2012 — Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883. Skia usado en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores que provocan una operación de escritura fuera de rango. Vulnerabilidad distinta de CVE-2012-2883. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-2879
https://notcve.org/view.php?id=CVE-2012-2879
26 Sep 2012 — Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document. Google Chrome anterior a v22.1229.79 permite a a atacantes remotos provocar una denegación de servicio (corrupción de topología DOM) a través de un documento manipulado. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-2890
https://notcve.org/view.php?id=CVE-2012-2890
26 Sep 2012 — Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document. Vulnerabilida de error en la gestión de recursos en la funcionalidad PDF en Google Chrome antes de v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otro impacto no especificado a través de un documento manipulado. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-399: Resource Management Errors •
CVE-2012-2876
https://notcve.org/view.php?id=CVE-2012-2876
26 Sep 2012 — Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. Vulnerabilidad de desbordamiento de búfer en la optimización de la funcionalidad SSE2 en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores desconocidos. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-2892
https://notcve.org/view.php?id=CVE-2012-2892
26 Sep 2012 — Unspecified vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to bypass the pop-up blocker via unknown vectors. Vulnerabilidad no especificada en Google Chrome anteriores a v22.0.1229.79 permite a atacantes remotos evitar el bloqueo del menú desplegable mediante vectores desconocidos. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html •
CVE-2012-2893 – libxslt: Heap-double-free in xmlFreeNodeList
https://notcve.org/view.php?id=CVE-2012-2893
26 Sep 2012 — Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms. Vulnerabilidad de doble liberación en libxslt en Google Chrome anterior a 22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores relacionados con las transformaciones XSL. Multiple Denial of Service vulnerabilities have been fo... • http://git.chromium.org/gitweb/?p=chromium.git%3Ba=commit%3Bh=9a5da8e7d4b6f3454614b0331a51bf29c966f556 • CWE-399: Resource Management Errors •
CVE-2012-2897
https://notcve.org/view.php?id=CVE-2012-2897
26 Sep 2012 — The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability." Los controlado... • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-4907
https://notcve.org/view.php?id=CVE-2012-4907
13 Sep 2012 — Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to have an unspecified impact via a crafted web page. Google Chrome antes de v18.0.1025308 en Android no restringe correctamente acceso desde el código JavaScript a Android API, lo que permite a atacantes remotos tener un impacto no especificado a través de una página web maliciosa. • http://googlechromereleases.blogspot.com/2012/09/chrome-for-android-update.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-4905 – Google Chrome for Android - com.android.browser.application_id Intent Extra Data Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-4905
13 Sep 2012 — Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)." Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en Google Chrome antes de v18.0.1025308 en Android permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un 'extra' en un objeto 'Intent'. Se trata de un problema también conocido como "Universal XSS ... • https://www.exploit-db.com/exploits/37792 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •