
CVE-2012-3489 – postgresql: File disclosure through XXE in xmlparse by DTD validation
https://notcve.org/view.php?id=CVE-2012-3489
03 Oct 2012 — The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue. La función xml_parse en el soporte libxml2 en el componente de servidor cen... • http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2012-2887
https://notcve.org/view.php?id=CVE-2012-2887
26 Sep 2012 — Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving onclick events. Vulnerabilidad de uso de memoria después de su liberación en Google Chrome anterior a 22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores relativos a los eventos "onclick". • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-399: Resource Management Errors •

CVE-2012-2885
https://notcve.org/view.php?id=CVE-2012-2885
26 Sep 2012 — Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit. Vulnerabilidad de doble liberación en Google Chrome anteriores a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otros impactos no determinados a través de vectores relacionados con la salida de la aplicación. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-399: Resource Management Errors •

CVE-2012-2884
https://notcve.org/view.php?id=CVE-2012-2884
26 Sep 2012 — Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. Skia usado en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio (lectura fuera de rango) a través de vectores no especificados. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-2874
https://notcve.org/view.php?id=CVE-2012-2874
26 Sep 2012 — Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883. Skia usado en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores que provocan una operación de escritura fuera de rango. Vulnerabilidad distinta de CVE-2012-2883. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-2878
https://notcve.org/view.php?id=CVE-2012-2878
26 Sep 2012 — Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling. Vulnerabilidad de liberación después del uso en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores relativos al manejo de plugins. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-399: Resource Management Errors •

CVE-2012-2881
https://notcve.org/view.php?id=CVE-2012-2881
26 Sep 2012 — Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via unknown vectors. Google Chrome anterio r av22.0.1229.79 no maneja adecuadamente los plugin, lo que permite a atacantes remotos provocar una denegación de servicio (corrupción de árbol DOM) u otro tipo de impacto a través de vectores desconocidos. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-2882
https://notcve.org/view.php?id=CVE-2012-2882
26 Sep 2012 — FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue. FFmpeg usado en Google Chrome anterior a v22.0.1229.79 no maneja adecuadamente los contenedores OGG, lo que permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores desconocidos relativos al tema "wild pointer... • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-20: Improper Input Validation •

CVE-2012-2879
https://notcve.org/view.php?id=CVE-2012-2879
26 Sep 2012 — Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document. Google Chrome anterior a v22.1229.79 permite a a atacantes remotos provocar una denegación de servicio (corrupción de topología DOM) a través de un documento manipulado. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-2880
https://notcve.org/view.php?id=CVE-2012-2880
26 Sep 2012 — Race condition in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the plug-in paint buffer. Vulnerabilidad de condición de carrera en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores relativos al plug-in "paint buffer". • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •