|
297781
|
- |
|
google
|
chrome
|
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive informatio…
|
CWE-295
Improper Certificate Validation
|
CVE-2011-3061
|
2024-11-21 10:29 |
2012-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297782
|
- |
|
google apple
|
chrome itunes safari iphone_os
|
Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
|
CWE-125
Out-of-bounds Read
|
CVE-2011-3060
|
2024-11-21 10:29 |
2012-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297783
|
- |
|
google apple
|
chrome itunes safari iphone_os
|
Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
|
CWE-125
Out-of-bounds Read
|
CVE-2011-3059
|
2024-11-21 10:29 |
2012-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297784
|
- |
|
google apple
|
chrome mac_os_x iphone_os
|
Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2011-3058
|
2024-11-21 10:29 |
2012-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297785
|
- |
|
google opensuse
|
chrome opensuse
|
Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which allows remote attackers to cause a denial of service (disrupted system requests) via a crafted extensi…
|
NVD-CWE-Other
|
CVE-2011-3049
|
2024-11-21 10:29 |
2012-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297786
|
- |
|
google
|
chrome
|
Google V8, as used in Google Chrome before 17.0.963.83, allows remote attackers to cause a denial of service via vectors that trigger an invalid read operation.
|
CWE-125
Out-of-bounds Read
|
CVE-2011-3057
|
2024-11-21 10:29 |
2012-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297787
|
- |
|
google opensuse apple
|
chrome opensuse iphone_os safari
|
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
|
CWE-346
Origin Validation Error
|
CVE-2011-3056
|
2024-11-21 10:29 |
2012-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297788
|
- |
|
google opensuse
|
chrome opensuse
|
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecif…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2011-3055
|
2024-11-21 10:29 |
2012-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297789
|
- |
|
google opensuse
|
chrome opensuse
|
The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vector…
|
CWE-269
Improper Privilege Management
|
CVE-2011-3054
|
2024-11-21 10:29 |
2012-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297790
|
- |
|
google apple opensuse
|
chrome itunes safari iphone_os opensuse
|
Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.
|
CWE-416
Use After Free
|
CVE-2011-3053
|
2024-11-21 10:29 |
2012-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|