CVE-2012-2874
https://notcve.org/view.php?id=CVE-2012-2874
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883. Skia usado en Google Chrome anterior a v22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores que provocan una operación de escritura fuera de rango. Vulnerabilidad distinta de CVE-2012-2883. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html https://code.google.com/p/chromium/issues/detail?id=132398 https://exchange.xforce.ibmcloud.com/vulnerabilities/78835 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15856 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-2889
https://notcve.org/view.php?id=CVE-2012-2889
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Chrome anteriores a v22.0.1229.79, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores que implican "frames" también conocido como "Universal XSS (UXSS)." • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html http://support.apple.com/kb/HT5642 https://code.google.com/p/chromium/issues/detail?id=143439 https://exchange.xforce.ibmcloud.com/vulnerabilities/78823 https://oval.cisecurity.org/repository/search/de • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2882
https://notcve.org/view.php?id=CVE-2012-2882
FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue. FFmpeg usado en Google Chrome anterior a v22.0.1229.79 no maneja adecuadamente los contenedores OGG, lo que permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores desconocidos relativos al tema "wild pointer". • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html https://chromiumcodereview.appspot.com/10829204 https://code.google.com/p/chromium/issues/detail?id=140647 https://exchange.xforce.ibmcloud.com/vulnerabilities/78839 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15688 https://src.chromium.org/viewvc/chrome?view=rev&revision=150239 • CWE-20: Improper Input Validation •
CVE-2012-2887
https://notcve.org/view.php?id=CVE-2012-2887
Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving onclick events. Vulnerabilidad de uso de memoria después de su liberación en Google Chrome anterior a 22.0.1229.79, permite a atacantes remotos provocar una denegación de servicio u otro tipo de impacto a través de vectores relativos a los eventos "onclick". • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html https://code.google.com/p/chromium/issues/detail?id=143609 https://exchange.xforce.ibmcloud.com/vulnerabilities/78828 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15797 • CWE-399: Resource Management Errors •
CVE-2012-2896
https://notcve.org/view.php?id=CVE-2012-2896
Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. Vulnerabilidad de desbordamiento de entero en la implementación WebGL en Google Chrome antes de v22.0.1229.79 en Mac OS X, permite a atacantes remotos causar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores desconocidos. • http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html https://code.google.com/p/chromium/issues/detail?id=145544 https://exchange.xforce.ibmcloud.com/vulnerabilities/78831 • CWE-189: Numeric Errors •