Page 331 of 3367 results (0.017 seconds)

CVSS: 10.0EPSS: 0%CPEs: 87EXPL: 0

01 Apr 2010 — The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors. La infraestructura sandbox en Google Chrome en versiones anteriores a la 4.1.249.1036 no usa de manera apropiada los punteros, lo que tiene un impacto y unos vectores de ataque no especificados. • http://code.google.com/p/chromium/issues/detail?id=28804 • CWE-399: Resource Management Errors •

CVSS: 10.0EPSS: 0%CPEs: 85EXPL: 0

01 Apr 2010 — Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors. Múltiples condiciones de carrera en la infraestructura sandbox en Google Chrome en versiones anteriores a la 4.1.249.1036 tienen un impacto y unos vectores de ataque no especificados. • http://code.google.com/p/chromium/issues/detail?id=28804 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

01 Apr 2010 — Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors. Google Chrome en versiones anteriores a la 4.1.249.1036 no tiene el comportamiento esperado al intentar borrar los Web SQL Databases y limpiar el estado Strict Transport Security (STS) lo que tiene un impacto y unos vectores de ataque no especificados. • http://code.google.com/p/chromium/issues/detail?id=30801 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.8EPSS: 89%CPEs: 54EXPL: 5

19 Mar 2010 — Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences. Vulnerabilidad de consumo en la pila en la función WebCore:: CSSSelector en WebKit, utilizado en Apple Safari v4.0.4, Apple Safari en iPhone OS y ... • https://www.exploit-db.com/exploits/11574 • CWE-399: Resource Management Errors •

CVSS: 9.3EPSS: 6%CPEs: 49EXPL: 0

18 Feb 2010 — Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attackers to execute arbitrary code in the Chrome sandbox or cause a denial of service (memory corruption and application crash) via vectors involving CANVAS elements. Múltiples desbordamientos de enteros en Skia, usado en Google Chrome anterior a v4.0.249.78 , permite a atacantes remotos ejecutar código arbitrario en la zona de seguridad de Chrome (sandbox) o causar una denegación de servicio (corrupción de la memo... • http://code.google.com/p/chromium/issues/detail?id=24071 • CWE-189: Numeric Errors •

CVSS: 9.8EPSS: 0%CPEs: 47EXPL: 0

18 Feb 2010 — The ParamTraits::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not use the correct variables in calculations designed to prevent integer overflows, which allows attackers to leverage renderer access to cause a denial of service or possibly have unspecified other impact via bitmap data, related to deserialization. La función ParamTraits::Read en common/common_param_traits.cc en Google Chrome anterior a v4.0.249.78 no utiliza las variables correctas... • http://code.google.com/p/chromium/issues/detail?id=31307 • CWE-189: Numeric Errors •

CVSS: 9.3EPSS: 0%CPEs: 48EXPL: 0

18 Feb 2010 — Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut. Google Chrome anterior a v4.0.249.78 en Windows no realiza la codificación esperada, escapando, y entrecomillando para la URL en el argumento --app en un acceso directo de escritorio , lo cua... • http://code.google.com/p/chromium/issues/detail?id=23693 •

CVSS: 9.3EPSS: 14%CPEs: 47EXPL: 1

18 Feb 2010 — Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site. Vulnerabilidad uso después de la liberación (use-after-free) en Google Chrome anterior a v4.0.249.78 permite a atacantes remotos asistidos por usuarios provocar una denegación de servicio (cuelgue de aplicación) o posibleme... • https://www.exploit-db.com/exploits/33664 • CWE-399: Resource Management Errors •

CVSS: 7.5EPSS: 0%CPEs: 47EXPL: 0

18 Feb 2010 — Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging. Google Chrome anterior a v4.0.249.78 envía una dirección URL https en la cabecera Referer de una petición HTTP en determinadas circunstancias involucrando la redirección https a http, lo cual permite a los servidores HTTP remotos obtener información sens... • http://code.google.com/p/chromium/issues/detail?id=29920 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.8EPSS: 1%CPEs: 49EXPL: 0

18 Feb 2010 — WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method. WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp en WebKit anterior a r52401 , usado en Google Chrome, anterior a v4.0.249.78, permite a atacantes remotos saltar la política de mismo origen (Same Origin Policy) a través de vectores que implica el método window.open. • http://code.google.com/p/chromium/issues/detail?id=30660 • CWE-264: Permissions, Privileges, and Access Controls •