| OSVDB ID | Disclosure Date | Title |
|
72791
Description:
(Description Provided by CVE) : The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
|
2011-06-07
|
Google Chrome DOM Unspecified Same Origin Policy Bypass
|
|
72479
Description:
Google Chrome contains a use-after-free flaw related to DOM URL handling that may allow an attacker to potentially execute arbitrary code. No further details have been provided.
|
2011-03-08
|
Google Chrome DOM URL Handling Use-after-free Remote Code Execution
|
|
62315
Description:
(Description Provided by CVE) : Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.
|
2010-02-10
|
Google Chrome Domain Name Resolution Proxy List Interpretation Information Disclosure
|
|
74695
Description:
(Description Provided by CVE) : Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
|
2011-08-22
|
Google Chrome Double Free Unspecified libxml XPath Handling Issue
|
|
75560
Description:
(Description Provided by CVE) : Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
|
2011-09-16
|
Google Chrome Double-free libxml XPath Handling Remote Code Execution
|
|
76547
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assisted remote attack vectors.
|
2011-10-25
|
Google Chrome Download Filename Whitespace Stripping Issue
|
|
78944
Description:
(Description Provided by CVE) : Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes it easier for remote attackers to spoof the URL bar via unspecified vectors.
|
2012-02-08
|
Google Chrome Drag + Drop Feature URL Bar Spoofing Weakness
|
|
70989
Description:
Google Chrome contains a flaw related to the failure to properly restrict cross-origin drag and drop operations that may allow a remote attacker to bypass the Same Origin Policy. No further details have been provided.
|
2011-02-03
|
Google Chrome Drag and Drop Same Origin Policy Bypass
|
|
65029
Description:
(Description Provided by CVE) : Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the "drag + drop" functionality.
|
2010-05-25
|
Google Chrome Drag and Drop Unspecified Memory Error
|
|
76546
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
|
2011-10-25
|
Google Chrome Drag and Drop URL Bar Spoofing
|
|
74232
Description:
(Description Provided by CVE) : The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
|
2011-08-02
|
Google Chrome Drag-and-Drop Implementation Access Restriction Bypass
|
|
72212
Description:
Google Chrome contains a flaw related to the failure to properly handle drop-down lists, which results in a stale pointer condition that may allow a remote attacker to cause a denial of service or have other unspecified impact. No further details have been provided.
|
2011-04-27
|
Google Chrome Drop-Down List Handling Unspecified Stale Pointer DoS
|
|
77037
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
|
2011-11-10
|
Google Chrome Editing Unspecified Use-after-free Remote Issue
|
|
74696
Description:
(Description Provided by CVE) : Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vectors related to empty origins.
|
2011-08-22
|
Google Chrome Empty Origin Same Origin Policy Bypass
|
|
63517
Description:
(Description Provided by CVE) : Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via an empty SVG element.
|
2010-03-17
|
Google Chrome Empty SVG Element Handling Memory Corruption
|
|
69171
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly handle the data types of event objects, allowing a context-dependent attacker to cause a denial of service or possibly have other unspecified impact.
|
2010-11-04
|
Google Chrome Event Object Data Type Handling Remote DoS
|
|
78934
Description:
(Description Provided by CVE) : Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of database usage.
|
2012-02-08
|
Google Chrome Excessive Database Usage Remote DoS
|
|
72789
Description:
(Description Provided by CVE) : Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.
|
2011-06-07
|
Google Chrome Extension chrome:// page Unspecified Injection Issue
|
|
65030
Description:
(Description Provided by CVE) : Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context, which has unspecified impact and remote attack vectors.
|
2010-05-25
|
Google Chrome Extension Context Unspecified Issue
|
|
72783
Description:
(Description Provided by CVE) : Google Chrome before 12.0.742.91 does not properly implement the framework for extensions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
|
2011-06-07
|
Google Chrome Extension Framework Stale Pointer Unspecified Issue
|
|
68109
Description:
(Description Provided by CVE) : Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors.
|
2010-09-14
|
Google Chrome Extension History Access Prompting Weakness Information Disclosure
|
|
74228
Description:
(Description Provided by CVE) : Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.
|
2011-08-02
|
Google Chrome Extension Installation Confirmation Weakness
|
|
70985
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly handle a missing key in an extension, allowing a context-dependent attacker to use a crafted extension to cause a denial of service.
|
2011-02-03
|
Google Chrome Extension Missing Key DoS
|
|
70453
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly handle extensions notification, allowing a remote attacker to cause an application crash denial of service.
|
2011-01-12
|
Google Chrome Extension Notification Handling Remote DoS
|
|
72785
Description:
(Description Provided by CVE) : Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions.
|
2011-06-07
|
Google Chrome Extension Tab Page Unspecified Script Injection
|
|
72200
Description:
Google Chrome contains a flaw related to the handling of extensions with 'tabs' permissions that may allow an attacker to gain access to local files. No further details have been provided.
|
2011-04-27
|
Google Chrome Extension Tabs Permission Arbitrary Local File Access
|
|
74235
Description:
(Description Provided by CVE) : The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.
|
2011-08-02
|
Google Chrome Extension Unspecified Homepage URL Sanitization Weakness
|
|
72782
Description:
(Description Provided by CVE) : Google Chrome before 12.0.742.91 allows remote attackers to bypass intended access restrictions via vectors related to extensions.
|
2011-06-07
|
Google Chrome Extensions Unspecified Access Restriction Bypass
|
|
69664
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly restrict file dialog generation, and will allow an attacker to cause a loss of availability via a maliciously crafted website.
|
2010-12-02
|
Google Chrome File Dialog Generation Remote DoS
|
|
67458
Description:
(Description Provided by CVE) : Google Chrome before 5.0.375.127 does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
|
2010-08-19
|
Google Chrome File Dialog Implementation Weakness Memory Corruption DoS
|