CVE-2012-5376
https://notcve.org/view.php?id=CVE-2012-5376
The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging access to a renderer process, a different vulnerability than CVE-2012-5112. La implementación de Inter-process Communication (IPC) en Google Chrome anteriores a v22.0.1229.94 permite a atacantes remotos evitar las restricciones del entorno de ejecución seguro "sandbox" establecidos y escribir en ficheros aprovechando el acceso a procesos de renderizado, es una vulnerabilidad distinta a CVE-2012-5112. • http://blog.chromium.org/2012/10/pwnium-2-results-and-wrap-up_10.html http://code.google.com/p/chromium/issues/detail?id=154983 http://code.google.com/p/chromium/issues/detail?id=154987 http://googlechromereleases.blogspot.com/2012/10/stable-channel-update_6105.html http://osvdb.org/86156 http://secunia.com/advisories/50954 https://exchange.xforce.ibmcloud.com/vulnerabilities/79186 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15156 • CWE-269: Improper Privilege Management •
CVE-2012-5108
https://notcve.org/view.php?id=CVE-2012-5108
Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices. Condición de carrera en Google Chorme antes de v22.0.1229.92, permite a atacantes remotos ejecutar código de su elección a través de vectores relacionados con dispositivos de audio. • http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html https://code.google.com/p/chromium/issues/detail?id=147499 https://exchange.xforce.ibmcloud.com/vulnerabilities/79064 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15651 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2012-5111
https://notcve.org/view.php?id=CVE-2012-5111
Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors. Google Chrome antes de v22.0.1229.92 no monitoriza los bloqueos de complementos Pepper, lo que tiene un impacto no especificado y vectores de ataque remotos. • http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html http://osvdb.org/86121 https://code.google.com/p/chromium/issues/detail?id=151895 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15517 •
CVE-2012-5110
https://notcve.org/view.php?id=CVE-2012-5110
The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. El compositor en Google Chorme antes de v22.0.1229.92, permite a atacantes remotos provocar una denegación de servicio (lectura fuera de límites) a través de vectores no especificados. • http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html https://code.google.com/p/chromium/issues/detail?id=151449 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14901 • CWE-125: Out-of-bounds Read •
CVE-2012-2900
https://notcve.org/view.php?id=CVE-2012-2900
Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors. Skia, como se usa en Google Chrome antes de v22.0.1229.92, no renderiza apropiadamente el texto, lo que permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o posiblemente tener otros impactos a través de vectores no especificados. • http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html https://code.google.com/p/chromium/issues/detail?id=138208 https://exchange.xforce.ibmcloud.com/vulnerabilities/79063 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15725 •