Skip to main content

Google Chrome Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 6 Sep 2010 4380 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Google Chrome, which could be exploited by attackers to bypass security restrictions, manipulate certain information or compromise a vulnerable system.

1. A memory corruption error related to focus handling, which could be exploited to execute arbitrary code.

2. A memory corruption error related to SVG filters, which could be exploited to execute arbitrary code.

3. A use-after-free error in Notifications presenter, which could be exploited to execute arbitrary code.

4. A memory corruption error related to Notification permissions, which could be exploited to execute arbitrary code.

5. An error when handling blank frame targets, which could be exploited to bypass the Pop-up blocker.

6. An error related to homographic sequences, which could allow URL bar visual spoofing.

7. An insecure restrictions being set on clipboard content.

8. An unspecified error which could allow attackers to enumerate installed extensions.

9. An unspecified error related to WebSockets, which could cause a browser NULL crash.

10. An integer errors in WebSockets, which could be exploited to execute arbitrary code.

11. A memory corruption error related to counter nodes, which could be exploited to execute arbitrary code.

12. The browser storing excessive autocomplete entries.

13. A sandbox parameter deserialization error.

14. An unspecified error which could cause a cross-origin image theft.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Google Chrome versions prior to 6.0.472.53

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link