CVE-2014-1710
https://notcve.org/view.php?id=CVE-2014-1710
The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service (GPU command-buffer memory corruption) or possibly have unspecified other impact via unknown vectors. La función AsyncPixelTransfersCompletedQuery::End en gpu/command_buffer/service/query_manager.cc en Google Chrome, utilizado en Google Chrome OS anterior a 33.0.1750.152, no comprueba si cierta posición está dentro de los límites de un segmento de memoria compartida, lo que permite a atacantes remotos causar una denegación de servicio (corrupción de memoria de comando de buffer de GPU) o posiblemente tener otro impacto no especificado a través de vectores desconocidos. • http://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.html https://code.google.com/p/chromium/issues/detail?id=351852 https://src.chromium.org/viewvc/chrome?revision=256723&view=revision https://src.chromium.org/viewvc/chrome?revision=256918&view=revision • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-1708
https://notcve.org/view.php?id=CVE-2014-1708
The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which allows remote attackers to execute arbitrary code via unspecified vectors. La implementación boot en Google Chrome OS anterior a 33.0.1750.152 no considera debidamente persistencia de archivo, lo que permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados. • http://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.html https://code.google.com/p/chromium/issues/detail?id=344051 •
CVE-2013-2833
https://notcve.org/view.php?id=CVE-2013-2833
Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships involving Elements and DrawElements. Vulnerabilidad usar-despues-de-liberar en el plug-in 03D en Google Chrome OS anterior a v26.0.1410.57 permite a atacantes remotos causar una denegación de servicio o posiblemente tener un impacto no especificado mediante vectores relacionados con el manejo inadecuado de las relaciones de propiedad comprenden Elements y DrawElements. • http://git.chromium.org/gitweb/?p=chromiumos/overlays/chromiumos-overlay.git%3Ba=commit%3Bh=9181705680e1f53fd1e895ebe84c1b7f18c5c380 http://googlechromereleases.blogspot.com/2013/04/stable-channel-update-for-chrome-os.html https://code.google.com/p/chromium/issues/detail?id=227181 • CWE-399: Resource Management Errors •
CVE-2013-2834
https://notcve.org/view.php?id=CVE-2013-2834
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2835. Google Chrome OS anterior a v26.0.1410.57 no fuerza correctamente las restricciones de origen para el O3D y el plugin Google Talk, permitiendo a atacantes remotos eludir el mecanismo de protección de lista blanca de dominios (domain-whitelist) mediante un sitio web manipulado, una vulnerabilidad diferente a CVE-2013-2835. • http://git.chromium.org/gitweb/?p=chromiumos/overlays/chromiumos-overlay.git%3Ba=commit%3Bh=9181705680e1f53fd1e895ebe84c1b7f18c5c380 http://googlechromereleases.blogspot.com/2013/04/stable-channel-update-for-chrome-os.html https://code.google.com/p/chromium/issues/detail?id=227158 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2013-2835
https://notcve.org/view.php?id=CVE-2013-2835
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834. Google Chrome OS anterior a v26.0.1410.57 no fuerza correctamente las restricciones de origen para el O3D y el plugin Google Talk, permitiendo a atacantes remotos eludir el mecanismo de protección de lista blanca de dominios (domain-whitelist) mediante un sitio web manipulado, una vulnerabilidad diferente a CVE-2013-2834. • http://googlechromereleases.blogspot.com/2013/04/stable-channel-update-for-chrome-os.html https://code.google.com/p/chromium/issues/detail?id=196456 • CWE-264: Permissions, Privileges, and Access Controls •