Page 636 of 3367 results (0.018 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 1

The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted extension. La función ThemeInstalledInfoBarDelegate::Observe en browser/extensions/theme_installed_infobar_delegate.cc en Google Chrome anterior v8.0.552.224 y Chrome OS anterior v8.0.552.343 no maneja adecuadamente la cuenta de iteracción incorrecta por extensión, lo que permite a usuarios asistidos remotamente causar una denegación de servicio (caída aplicación) a través de una extensión manipulada. • http://code.google.com/p/chromium/issues/detail?id=60761 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.html http://secunia.com/advisories/42648 http://src.chromium.org/viewvc/chrome?view=rev&revision=68112 http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml http://www.securityfocus.com/bid/45390 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14427 • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 1%CPEs: 4EXPL: 0

Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers." Google Chrome, en versiones anteriores a la 8.0.552.224 y Chrome OS, en versiones anteriores a la 8.0.552.343 no soporta adecuadamente el cursor, lo que permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otro impacto no especificado mediante vectores desconocidos que dan lugar a "stale pointers." • http://code.google.com/p/chromium/issues/detail?id=64959 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.html http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html http://secunia.com/advisories/42648 http://www.debian.org/security/2011/dsa-2188 http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml http://www.securityfocus.com/bid/45390 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14323 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site. Google Chrome antes de v8.0.552.215 no restringe adecuadamente el acceso de lectura a los vídeos de derivados de elementos CANVAS, lo que permite a atacantes remotos evitar la política del mismo origen y obtener los datos de video potencialmente sensibles a través de un sitio web debidamente modificado. • http://code.google.com/p/chromium/issues/detail?id=55745 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.html http://secunia.com/advisories/42472 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11610 https://technet.microsoft.com/library/security/msvr11-002 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 2%CPEs: 3EXPL: 1

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events. Vulnerabilidad de uso después de liberación en Google Chrome antes v8.0.552.215 permite a atacantes remotos provocar una denegación de servicio a través de vectores relacionados con el manejo de eventos de arrastre de ratón. • http://code.google.com/p/chromium/issues/detail?id=63051 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.html http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html http://secunia.com/advisories/42472 http://www.debian.org/security/2011/dsa-2188 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12129 • CWE-416: Use After Free •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via malformed video content that triggers an indexing error. Google Chrome antes de v8.0.552.215 permite a atacantes remotos provocar una denegación de servicio (por caída de aplicación) o posiblemente tener un impacto no especificado a través de un vídeo con formato incorrecto que provoca un error de indexación. • http://code.google.com/p/chromium/issues/detail?id=62127 http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.html http://secunia.com/advisories/42472 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12284 •