| OSVDB ID | Disclosure Date | Title |
|
74245
Description:
(Description Provided by CVE) : Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows remote attackers to bypass intended access restrictions via a crafted web site, related to a "cross-frame function leak."
|
2011-08-02
|
Google Chrome Cross-frame Function Leak Unspecified Access Restriction Bypass
|
|
72475
Description:
Google Chrome contains a flaw related to the leaking of cross-origin error messages which may allow a remote attacker to bypass the same origin policy.
|
2011-03-08
|
Google Chrome Cross-Origin Error Message Leak Same Origin Policy Bypass
|
|
72264
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered by malformed CSS token sequences, and will result in loss of availability for the application.
|
2011-03-24
|
Google Chrome CSS Handling Stale Pointer DoS
|
|
72284
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered by an unspecified CSS stale pointer issue, and will result in loss of availability for the application.
|
2011-02-28
|
Google Chrome CSS Handling Unspecified Stale Pointer DoS
|
|
73507
Description:
(Description Provided by CVE) : Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
|
2011-06-28
|
Google Chrome CSS Parsing Memory Corruption
|
|
77711
Description:
(Description Provided by CVE) : The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
|
2011-12-13
|
Google Chrome CSS Property Array Unspecified Remote Memory Corruption
|
|
66049
Description:
(Description Provided by CVE) : The Cascading Style Sheets (CSS) implementation in Google Chrome before 5.0.375.99 does not properly perform style rendering, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
|
2010-07-02
|
Google Chrome CSS Style Rendering Weakness Memory Corruption DoS
|
|
70456
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly handle Cascading Style Sheets token sequences in conjunction with CANVAS elements, allowing a remote attacker to cause a denial of service via a 'stale pointer'.
|
2011-01-12
|
Google Chrome CSS Token Sequence CANVAS Element Stale Pointer Remote DoS
|
|
70457
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly handle Cascading Style Sheets token sequences in conjunction with cursors, allowing a remote attacker to cause a denial of service via a 'stale pointer'.
|
2011-01-12
|
Google Chrome CSS Token Sequence Cursor Stale Pointer Remote DoS
|
|
70105
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly parse CSS token sequences, allowing a remote attacker to cause an out-of-bounds read denial of service via unspecified vectors.
|
2010-12-13
|
Google Chrome CSS Token Sequence Out-of-bounds Read Remote DoS
|
|
72780
Description:
(Description Provided by CVE) : The Cascading Style Sheets (CSS) implementation in Google Chrome before 12.0.742.91 does not properly restrict access to the visit history, which allows remote attackers to obtain sensitive information via unspecified vectors.
|
2011-06-07
|
Google Chrome CSS Visit History Unspecified Remote Information Disclosure
|
|
77604
Description:
(Description Provided by CVE) : The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.
|
2010-06-08
|
Google Chrome CSS visited Pseudo-class Handling Browsing History Disclosure
|
|
51732
Description:
Unknown / Incomplete
|
2008-09-05
|
Google Chrome Current Session Cleartext Web Sites Credential Disclosure
|
|
70106
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly perform cursor handling, allowing a remote attacker to cause a denial of service via unknown vectors leading to 'stale pointers'.
|
2010-12-13
|
Google Chrome Cursor Handling Stale Pointer Remote DoS
|
|
74230
Description:
(Description Provided by CVE) : Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended content restrictions via a crafted web site.
|
2011-08-02
|
Google Chrome Dangerous File Download Confirmation Weakness
|
|
72198
Description:
Google Chrome contains a linked-list race condition related to database handling that may allow an attacker to cause a denial of service or have other, unspecified impact. No further details have been provided.
|
2011-04-27
|
Google Chrome Database Handling Linked-List Race Condition DoS
|
|
72487
Description:
Google Chrome contains a flaw related to the DataView object handling missing a args.IsConstructCall() check that may allow an attacker to potentially execute arbitrary code. No further details have been provided.
|
2011-03-08
|
Google Chrome DataView Object Handling Remote Code Execution
|
|
69170
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program accesses a frame object after it has been destroyed, allowing a context-dependent attacker to cause a denial of service or possibly have other unspecified impact.
|
2010-11-04
|
Google Chrome Destroyed Frame Object Access Remote DoS
|
|
64001
Description:
(Description Provided by CVE) : Unspecified vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to access local files via vectors related to "developer tools."
|
2010-04-21
|
Google Chrome Developer Tools Unspecified Local File Access
|
|
72786
Description:
(Description Provided by CVE) : Use-after-free vulnerability in the developer tools in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
|
2011-06-07
|
Google Chrome Developer Tools User-after-free Unspecified Issue
|
|
74233
Description:
(Description Provided by CVE) : Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.
|
2011-08-02
|
Google Chrome Developer-Mode NPAPI Extension Installation Confirmation Weakness
|
|
72274
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered by an unspecified device orientation issue, and will result in loss of availability for the application.
|
2011-02-28
|
Google Chrome Device Orientation Unspecified DoS
|
|
74255
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.
|
2011-08-02
|
Google Chrome Display Box Rendering Use-after-free Unspecified Remote DoS
|
|
68101
Description:
(Description Provided by CVE) : Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.
|
2010-09-14
|
Google Chrome Document API Parsing Use-after-free DoS
|
|
68387
Description:
(Description Provided by CVE) : Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.
|
2010-09-17
|
Google Chrome Document Origin Properties Pollution Unspecified Issue
|
|
72483
Description:
Google Chrome contains a use-after-free flaw related to the document script lifetime handling that may allow an attacker to potentially execute arbitrary code. No further details have been provided.
|
2011-03-08
|
Google Chrome Document Script Lifetime Handling Use-after-free Remote Code Execution
|
|
61792
Description:
(Description Provided by CVE) : WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
|
2010-01-09
|
Google Chrome document.styleSheets[0].href Property URL Redirect Target Disclosure
|
|
72216
Description:
Google Chrome contains a flaw related to the failure to properly handle DOM id maps that may lead to a dangling pointer condition, allowing a remote attacker to cause a denial of service or have other unspecified impact. No further details have been provided.
|
2011-04-27
|
Google Chrome DOM id Map Unspecified Dangling Pointer DoS
|
|
72218
Description:
Google Chrome contains a use-after-free error related to DOM id handling that may allow a context-dependent attacker to use a crafted HTML document to cause a denial of service or have other unspecified impact. No further details have been provided.
|
2011-04-27
|
Google Chrome DOM id Use-after-free Unspecified DoS
|
|
70467
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly perform DOM node removal, allowing a remote attacker to cause a denial of service via a 'stale rendering node'.
|
2011-01-12
|
Google Chrome DOM Node Removal Stale Rendering Node Remote DoS
|