| OSVDB ID | Disclosure Date | Title |
|
72482
Description:
Google Chrome contains multiple flaws that may allow an attacker to bypass the pop-up blocker. No further details have been provided.
|
2011-03-08
|
Google Chrome Multiple Unspecified Pop-up Blocker Bypass
|
|
76552
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
|
2011-10-25
|
Google Chrome Multiple Unspecified Same Origin Policy Bypass
|
|
76556
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.
|
2011-10-25
|
Google Chrome Multiple Use-after-free Stale Style Sheet Handling Remote Code Execution
|
|
72207
Description:
Google Chrome contains a flaw related to mutation events in corrupt node trees that may allow a remote attacker to cause a denial of service or have other unspecified impact. No further details have been provided.
|
2011-04-19
|
Google Chrome Mutation Events Node Tree Corruption DoS
|
|
72211
Description:
Google Chrome contains a flaw related to navigation errors and interrupted loads that may allow a remote attacker to spoof the URL bar. No further details have been provided.
|
2011-04-27
|
Google Chrome Navigation Error Interrupted Load URL Spoofing Weakness
|
|
68103
Description:
(Description Provided by CVE) : Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to nested SVG elements.
|
2010-09-14
|
Google Chrome Nested SVG Elements Use-after-free DoS
|
|
73562
Description:
(Description Provided by CVE) : The SPDY implementation in net/http/http_network_transaction.cc in Google Chrome before 11.0.696.14 drains the bodies from SPDY responses, which might allow remote SPDY servers to cause a denial of service (application exit) by canceling a stream.
|
2011-03-17
|
Google Chrome net/http/http_network_transaction.cc SPDY Response Stream Cancellation Remote DoS
|
|
70454
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the node-iteration implementation fails to properly handle pointers, allowing a remote attacker to cause a denial of service.
|
2011-01-12
|
Google Chrome Node-iteration Pointer Handling Remote DoS
|
|
75561
Description:
(Description Provided by CVE) : Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
|
2011-09-16
|
Google Chrome Non-Gallery Page Permission Weakness
|
|
67464
Description:
(Description Provided by CVE) : Google Chrome before 5.0.375.127 does not properly implement the notifications feature, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via unknown vectors.
|
2010-08-19
|
Google Chrome Notifications Feature Implementation Weakness Remote DoS
|
|
67861
Description:
(Description Provided by CVE) : The implementation of notification permissions in Google Chrome before 6.0.472.53 allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
|
2010-09-02
|
Google Chrome Notifications Permissions Implementation Unspecified Memory Corruption
|
|
67860
Description:
(Description Provided by CVE) : Use-after-free vulnerability in the Notifications presenter in Google Chrome before 6.0.472.53 allows attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
|
2010-09-02
|
Google Chrome Notifications Presenter Use-after-free DoS
|
|
73504
Description:
(Description Provided by CVE) : The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
|
2011-06-28
|
Google Chrome NPAPI String Handling Out-of-bounds Read Remote DoS
|
|
72484
Description:
Google Chrome contains a flaw related to the OGG container implementation that may allow an attacker to cause an out-of-bounds write and potentially execute arbitrary code. No further details have been provided.
|
2011-03-08
|
Google Chrome OGG Container Out-of-Bounds Write Remote Code Execution
|
|
67465
Description:
(Description Provided by CVE) : The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow remote attackers to obtain sensitive information by reading the network traffic generated by this feature.
|
2010-08-19
|
Google Chrome Omnibox Implementation Autosuggest Feature Password Entry Remote Information Disclosure
|
|
67265
Description:
Unknown / Incomplete
|
2010-06-24
|
Google Chrome Omnibox Loading Subresource Display Unspecified Issue
|
|
72280
Description:
Chrome contains a flaw that may allow a [REMOTE | LOCAL] denial of service. The issue is triggered by an unspecified pickle deserialization issue, and will result in loss of availability for the application.
|
2011-02-28
|
Google Chrome on 64-bit Linux Pickle Deserialization Out-of-bounds Read DoS
|
|
64481
Description:
(Description Provided by CVE) : Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.
|
2010-04-26
|
Google Chrome on HTC Hero marquee Tag Sequence Infinite Loop Remote DoS
|
|
65406
Description:
(Description Provided by CVE) : browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictions via vectors involving fchdir and chdir calls.
|
2010-06-09
|
Google Chrome on Linux browser/renderer_host/database_dispatcher_host.cc Sandbox Restriction Bypass
|
|
69168
Description:
Google Chrome on Linux is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a multiple integer overflows. With a specially crafted font, a context-dependent attacker can cause a denial of service or possibly have other unspecified impact.
|
2010-11-04
|
Google Chrome on Linux Crafted Font Unspecified Multiple Overflows
|
|
68104
Description:
(Description Provided by CVE) : Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors.
|
2010-09-14
|
Google Chrome on Linux Cursor Handling Weakness DoS
|
|
68108
Description:
(Description Provided by CVE) : Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
|
2010-09-14
|
Google Chrome on Linux Khmer Locale Implementation Weakness Unspecified Memory Corruption
|
|
68840
Description:
Google Chrome on Linux contains a flaw related to a failure to properly set the PATH environment variable that may allow an attacker to have an unspecified impact. No further details have been provided.
|
2010-10-19
|
Google Chrome on Linux PATH Environment Variable Setting Unspecified Issue
|
|
68842
Description:
Google Chrome on Linux contains a flaw related to the sandbox implementation's failure to properly constrain worker processes. This may allow a remote attacker to bypass access restrictions.
|
2010-10-19
|
Google Chrome on Linux Sandbox Worker Processes Unspecified Access Restriction Bypass
|
|
70984
Description:
Google Chrome on Mac OS X contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to mitigate an unspecified flaw in the SSL libraries, and will result in loss of availability for the program.
|
2011-02-03
|
Google Chrome on Mac OS X SSL Libraries Unspecified DoS
|
|
70982
Description:
Google Chrome on Mac OS X contains a flaw that may lead to an unauthorized information disclosure. A remote attacker may obtain potentially sensitive local file information via the 'stat()' system call.
|
2011-02-03
|
Google Chrome on Mac OS X stat() Call Sandbox Information Disclosure
|
|
51135
Description:
(Description Provided by CVE) : ** DISPUTED ** Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission."
|
2008-12-23
|
Google Chrome on Windows chromehtml: URI--renderer-path Option Arbitrary Remote Command Execution
|
|
62309
Description:
(Description Provided by CVE) : Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.
|
2010-01-25
|
Google Chrome on Windows Shortcut Character Escaping Arbitrary Program Execution
|
|
73647
Description:
(Description Provided by CVE) : Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20110510, the only disclosure is a vague advisory that possibly relates to multiple vulnerabilities or multiple products. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
|
2011-05-09
|
Google Chrome on Windows Unspecified Remote Code Execution
|
|
52642
Description:
(Description Provided by CVE) : ** DISPUTED ** Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue."
|
2009-01-29
|
Google Chrome onclick Action Crafted Element Arbitrary URL Visiting (ClickJacking)
|