CVE-2011-3098
- EPSS 0.03%
- Veröffentlicht 16.05.2012 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gain privileges via a Trojan horse plug-in in an unspecified directory.
CVE-2012-1823
- EPSS 94.39%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...
- EPSS 0.83%
- Veröffentlicht 01.05.2012 10:12:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
CVE-2012-0883
- EPSS 0.21%
- Veröffentlicht 18.04.2012 10:33:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apach...
- EPSS 1.9%
- Veröffentlicht 23.03.2012 10:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which allows remote attackers to cause a denial of service (disrupted system requests) via a crafted extension.
CVE-2011-3045
- EPSS 5.81%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 09.06.2025 16:15:22
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...
CVE-2011-3050
- EPSS 5.57%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-lette...
CVE-2011-3051
- EPSS 3.55%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the cross-fade f...
CVE-2011-3052
- EPSS 1.44%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The WebGL implementation in Google Chrome before 17.0.963.83 does not properly handle CANVAS elements, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2011-3053
- EPSS 4.45%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.