- EPSS 1.11%
- Veröffentlicht 10.07.2013 10:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to trigger unwanted extension change...
CVE-2013-2869
- EPSS 0.96%
- Veröffentlicht 10.07.2013 10:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted JPEG2000 image.
CVE-2013-2870
- EPSS 2.33%
- Veröffentlicht 10.07.2013 10:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
CVE-2013-2871
- EPSS 1.78%
- Veröffentlicht 10.07.2013 10:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
- EPSS 0.93%
- Veröffentlicht 10.07.2013 10:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Google Chrome before 28.0.1500.71 on Mac OS X does not ensure a sufficient source of entropy for renderer processes, which might make it easier for remote attackers to defeat cryptographic protection mechanisms in third-party components via unspecifi...
CVE-2013-2873
- EPSS 1.27%
- Veröffentlicht 10.07.2013 10:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a 404 HTTP status code during the loading of resources.
CVE-2013-2866
- EPSS 1.4%
- Veröffentlicht 19.06.2013 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows rem...
CVE-2013-2860
- EPSS 1.1%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.
CVE-2013-2861
- EPSS 1.1%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2013-2862
- EPSS 1.1%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.