CVE-2013-6652
https://notcve.org/view.php?id=CVE-2013-6652
Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for .. (dot dot) sequences or (2) lack of use of the \\?\ protection mechanism. Vulnerabilidad de salto de directorio en sandbox/win/src/named_pipe_dispatcher.cc en Google Chrome anterior a 33.0.1750.117 en Windows permite a atacantes remotos evadir restricciones de política named-pipe en el sandbox a través de vectores relacionados con (1) la falta de comprobaciones para las secuencias .. (punto punto) o (2) la falta de uso del mecanismo de protección "\\? • http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html https://code.google.com/p/chromium/issues/detail?id=334897 https://src.chromium.org/viewvc/chrome?revision=247511&view=revision • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2014-1681
https://notcve.org/view.php?id=CVE-2014-1681
Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and attack vectors, related to 12 "security fixes [that were not] either contributed by external researchers or particularly interesting." Múltiples vulnerabilidades no especificadas en Google Chrome anteriores a 32.0.1700.102 tienen un impacto y vectores de ataque desconocidos, relacionados con 12 "correciones de seguridad (que no lo fueron) de contribuciones externas o de un interés particular" • http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html http://osvdb.org/102633 https://exchange.xforce.ibmcloud.com/vulnerabilities/90975 •
CVE-2013-6650 – v8: incorrect handling of popular pages
https://notcve.org/view.php?id=CVE-2013-6650
The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages." La función StoreBuffer::ExemptPopularPages en store-buffer.cc de Google V8 anterior a la versión 3.22.24.16, tal y como se usa en Google Chrome anterior a la versión 32.0.1700.102, permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) o posiblemente tener otro impacto no especificado a través de vectores que desencadenen un manejo incorrecto de "páginas populares." • http://crbug.com/331444 http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html http://www.debian.org/security/2014/dsa-2862 https://code.google.com/p/v8/source/detail?r=18483 https://access.redhat.com/security/cve/CVE-2013-6650 https://bugzilla.redhat.com/show_bug.cgi?id=1059070 • CWE-20: Improper Input Validation CWE-480: Use of Incorrect Operator •
CVE-2013-6649
https://notcve.org/view.php?id=CVE-2013-6649
Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image. Vulnerabilidad de liberación de recursos en la función RenderSVGImage::paint en core/rendering/svg/RenderSVGImage.cpp de Blink, tal y como se usa en Google Chrome anterior a la versión 32.0.1700.102, permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otro impacto y vectores que involucren una imagen SVG de tamaño 0. • http://crbug.com/330420 http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html http://www.debian.org/security/2014/dsa-2862 https://src.chromium.org/viewvc/blink?revision=164536&view=revision • CWE-399: Resource Management Errors •
CVE-2013-6644
https://notcve.org/view.php?id=CVE-2013-6644
Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors. Múltiples vulnerabilidades sin especificar en Google Chrome anterior a la versión 32.0.1700.76 en Windows y anterior a 32.0.1700.77 en Mac OS X y Linux permite a atacantes provocar una denegación de servicio o posiblemente tener otro impacto mediante vectores desconocidos. • http://googlechromereleases.blogspot.com/2014/01/stable-channel-update.html http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html http://www.debian.org/security/2014/dsa-2862 https://code.google.com/p/chromium/issues/detail?id=269837 https://code.google.com/p/chromium/issues/detail?id=280352 https://code.google.com/p/chromium/issues/detail?id=304547 https://code.google.com/p/chromium/issues/detail?id=313743 https://code.google.com/p/chromium/issues/detail? • CWE-416: Use After Free •