18 Feb 2010 — Google Chrome before on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut. Google Chrome anterior a v4.0.249.78 en Windows no realiza la codificación esperada, escapando, y entrecomillando para la URL en el argumento --app en un acceso directo de escritorio , lo cua... • http://code.google.com/p/chromium/issues/detail?id=23693 •

CVE-2010-0655 – Mozilla Firefox 3.5.8 - Style Sheet redirection Information Disclosure
18 Feb 2010 — Use-after-free vulnerability in Google Chrome before allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site. Vulnerabilidad uso después de la liberación (use-after-free) en Google Chrome anterior a v4.0.249.78 permite a atacantes remotos asistidos por usuarios provocar una denegación de servicio (cuelgue de aplicación) o posibleme... • https://www.exploit-db.com/exploits/33664 • CWE-399: Resource Management Errors •

18 Feb 2010 — Google Chrome before sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging. Google Chrome anterior a v4.0.249.78 envía una dirección URL https en la cabecera Referer de una petición HTTP en determinadas circunstancias involucrando la redirección https a http, lo cual permite a los servidores HTTP remotos obtener información sens... • http://code.google.com/p/chromium/issues/detail?id=29920 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

18 Feb 2010 — browser/login/login_prompt.cc in Google Chrome before populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element. browser/login/login_prompt.cc en Google Chrome anterior v4.0.249.89 con un diálogo de autenticación con credenciales que fueron almacenadas por Pass... • http://code.google.com/p/chromium/issues/detail?id=32718 • CWE-255: Credentials Management Errors •

CVE-2010-0315 – Google Chrome 3.0 - Style Sheet redirection Information Disclosure
14 Jan 2010 — WebKit before r53607, as used in Google Chrome before, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element. WebKit anterior a versión r53607, tal como es usado en Chrome de Google anterior a versión, permite a los atacantes remotos detectar la URL de destino... • https://www.exploit-db.com/exploits/33562 •

13 Nov 2009 — The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page. La implementación de Cross-Origin Resource Sharing (CORS) en WebKit, tal como es usado en Safari de Apple anterior a versión 4.0.4 y Chrome d... • http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html • CWE-352: Cross-Site Request Forgery (CSRF) •

12 Nov 2009 — The Gears plugin in Google Chrome before allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting "SQL metadata into a bad state." El plugin Gears en Google Chrome, en versiones anteriores a la permite a usuarios remotos asistidos por el usuario provocar una denegación de servicio (corrupción de memoria y caída del plugin) o posiblemente ejecuta... • http://code.google.com/p/chromium/issues/detail?id=26179 •

12 Nov 2009 — WebKit before r50173, as used in Google Chrome before, allows remote attackers to cause a denial of service (CPU consumption) via a web page that calls the JavaScript setInterval method, which triggers an incompatibility between the WTF::currentTime and base::Time functions. WebKit en versiones anteriores a la r50173, tal como se usa en Google Chrome en versiones anteriores a la, permite a atacantes remotos provocar una denegación de servicio (consumo de CPU) mediante una página web qu... • http://code.google.com/p/chromium/issues/detail?id=25892 • CWE-399: Resource Management Errors •

12 Nov 2009 — Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (1) .mht and (2) .mhtml files, which are automatically executed by Internet Explorer 6; (3) .svg files, which are automatically executed by Safari; (4) .xml files; (5) .htt files; (6) .xsl files; (7) .xslt files; and (8) image files that are forbidden by the vi... • http://code.google.com/p/chromium/issues/detail?id=23979 • CWE-20: Improper Input Validation •

12 Nov 2009 — The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail. La función WebFrameLoaderClient::dispatchDidChangeLocationWithinPage en src/webkit/glue/webframeloaderclient_impl.cc en Google Chrome antes de permite a atacantes asistidos p... • http://code.google.com/p/chromium/issues/detail?id=22205 •