7.5

CVE-2013-0927

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.

Data is provided by the National Vulnerability Database (NVD)
GoogleChrome Os Version <= 26.0.1410.56
GoogleChrome Os Version26.0.1410.0
GoogleChrome Os Version26.0.1410.1
GoogleChrome Os Version26.0.1410.3
GoogleChrome Os Version26.0.1410.4
GoogleChrome Os Version26.0.1410.5
GoogleChrome Os Version26.0.1410.6
GoogleChrome Os Version26.0.1410.7
GoogleChrome Os Version26.0.1410.8
GoogleChrome Os Version26.0.1410.9
GoogleChrome Os Version26.0.1410.10
GoogleChrome Os Version26.0.1410.11
GoogleChrome Os Version26.0.1410.12
GoogleChrome Os Version26.0.1410.14
GoogleChrome Os Version26.0.1410.15
GoogleChrome Os Version26.0.1410.16
GoogleChrome Os Version26.0.1410.17
GoogleChrome Os Version26.0.1410.18
GoogleChrome Os Version26.0.1410.19
GoogleChrome Os Version26.0.1410.20
GoogleChrome Os Version26.0.1410.21
GoogleChrome Os Version26.0.1410.22
GoogleChrome Os Version26.0.1410.23
GoogleChrome Os Version26.0.1410.24
GoogleChrome Os Version26.0.1410.25
GoogleChrome Os Version26.0.1410.26
GoogleChrome Os Version26.0.1410.27
GoogleChrome Os Version26.0.1410.28
GoogleChrome Os Version26.0.1410.29
GoogleChrome Os Version26.0.1410.30
GoogleChrome Os Version26.0.1410.31
GoogleChrome Os Version26.0.1410.32
GoogleChrome Os Version26.0.1410.33
GoogleChrome Os Version26.0.1410.34
GoogleChrome Os Version26.0.1410.35
GoogleChrome Os Version26.0.1410.36
GoogleChrome Os Version26.0.1410.37
GoogleChrome Os Version26.0.1410.38
GoogleChrome Os Version26.0.1410.39
GoogleChrome Os Version26.0.1410.40
GoogleChrome Os Version26.0.1410.41
GoogleChrome Os Version26.0.1410.42
GoogleChrome Os Version26.0.1410.43
GoogleChrome Os Version26.0.1410.44
GoogleChrome Os Version26.0.1410.45
GoogleChrome Os Version26.0.1410.46
GoogleChrome Os Version26.0.1410.47
GoogleChrome Os Version26.0.1410.48
GoogleChrome Os Version26.0.1410.49
GoogleChrome Os Version26.0.1410.50
GoogleChrome Os Version26.0.1410.51
GoogleChrome Os Version26.0.1410.52
GoogleChrome Os Version26.0.1410.54
GoogleChrome Os Version26.0.1410.55
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.381
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.