![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3934
https://notcve.org/view.php?id=CVE-2009-3934
12 Nov 2009 — The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail. La función WebFrameLoaderClient::dispatchDidChangeLocationWithinPage en src/webkit/glue/webframeloaderclient_impl.cc en Google Chrome antes de 3.0.195.32 permite a atacantes asistidos p... • http://code.google.com/p/chromium/issues/detail?id=22205 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3932
https://notcve.org/view.php?id=CVE-2009-3932
12 Nov 2009 — The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting "SQL metadata into a bad state." El plugin Gears en Google Chrome, en versiones anteriores a la 3.0.195.32 permite a usuarios remotos asistidos por el usuario provocar una denegación de servicio (corrupción de memoria y caída del plugin) o posiblemente ejecuta... • http://code.google.com/p/chromium/issues/detail?id=26179 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3933
https://notcve.org/view.php?id=CVE-2009-3933
12 Nov 2009 — WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via a web page that calls the JavaScript setInterval method, which triggers an incompatibility between the WTF::currentTime and base::Time functions. WebKit en versiones anteriores a la r50173, tal como se usa en Google Chrome en versiones anteriores a la 3.0.195.32, permite a atacantes remotos provocar una denegación de servicio (consumo de CPU) mediante una página web qu... • http://code.google.com/p/chromium/issues/detail?id=25892 • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3931
https://notcve.org/view.php?id=CVE-2009-3931
12 Nov 2009 — Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (1) .mht and (2) .mhtml files, which are automatically executed by Internet Explorer 6; (3) .svg files, which are automatically executed by Safari; (4) .xml files; (5) .htt files; (6) .xsl files; (7) .xslt files; and (8) image files that are forbidden by the vi... • http://code.google.com/p/chromium/issues/detail?id=23979 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3456
https://notcve.org/view.php?id=CVE-2009-3456
29 Sep 2009 — Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Google Chrome, posiblemente v3.0.195.21 y ant... • http://www.securityfocus.com/bid/36479 • CWE-310: Cryptographic Issues •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3268
https://notcve.org/view.php?id=CVE-2009-3268
18 Sep 2009 — Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828. Google Chrome v1.0.154.48 y anteriores permite a atacantes remotos producir una denegación de servicio (consumo de CPU) a través de un envío automático de un formulario que contenga un elemento generador de claves, una vulnerabilidad relacionada con CVE-2009-1828. • http://websecurity.com.ua/3194 • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3263
https://notcve.org/view.php?id=CVE-2009-3263
18 Sep 2009 — Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Google Chrome 2.x y 3.x anteriores a 3.0.195.21 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de feeds (1) RSS o (2) Atom, ... • http://code.google.com/p/chromium/issues/detail?id=21238 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2008-7246 – Multiple Browsers - 'window.print()' Denial of Service
https://notcve.org/view.php?id=CVE-2008-7246
18 Sep 2009 — Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. Google Chrome v0.2.149.29 y anteriores permite a atacantes remotos producir una denegación de servicio (navegador inutilizado) mediante una llamada en bucle a la función window.print, también conocido como "ataque DoS de impresión", posiblemente relacionado con la vulnerabilidad CVE... • https://www.exploit-db.com/exploits/12509 • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3264
https://notcve.org/view.php?id=CVE-2009-3264
18 Sep 2009 — The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document. El método getSVGDocument en Google Chrome anteriores a v3.0.195.21 omite una comprobación de acceso inespecífica, lo que permite a servidores web remotos evitar la politica Same Originy dirigir ataques de ej... • http://code.google.com/p/chromium/issues/detail?id=21338 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-3011
https://notcve.org/view.php?id=CVE-2009-3011
31 Aug 2009 — Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: the JavaScript executes outside of the context of t... • http://websecurity.com.ua/3315 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •