DSA-2695-1
chromium-browser - several
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser | affected | Debian:7 | chromium-browser | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
chromium-browser - several
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser | affected | Debian:7 | chromium-browser | — |
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.
CVEs:CVE-2013-2842
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| iphone_os | affected | apple | — | — |
The Web Audio implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2013-2845
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.93 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2013-2836
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
CVEs:CVE-2013-2849
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
CVEs:CVE-2013-2848
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2013-2837
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome before 27.0.1453.93 does not properly perform a cast of an unspecified variable during handling of clipboard data, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2013-2839
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2846.
CVEs:CVE-2013-2840
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of Pepper resources.
CVEs:CVE-2013-2841
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of speech data.
CVEs:CVE-2013-2843
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style resolution.
CVEs:CVE-2013-2844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.
CVEs:CVE-2013-2846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2013-2847
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2013-2838
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| v8 | affected | — | — |
SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi applic...
CVEs:CVE-2013-2310
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android_smartphone | affected | willcom-inc | — | — |
| android_smartphone | affected | softbank | — | — |
| disney_mobile_android_smartphone | affected | softbank | — | — |
| mobile_wi-fi_router | affected | softbank | — | — |
| nec_3g_handset | affected | softbank | — | — |
| panasonic_3g_handset | affected | softbank | — | — |
| samsung_3g_handset | affected | softbank | — | — |
| sharp_3g_handset | affected | softbank | — | — |
| wi-fi_application | affected | willcom-inc | — | — |
| wi-fi_application | affected | softbank | — | — |
| wi-fi_spot_configuration_software | affected | softbank | — | — |
| windows_mobile_smartphone | affected | softbank | — | — |
| wisprclient | affected | softbank | — | — |
The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB Debugging mode, using Android Debug Bridge (adb) to establish a USB connection, dialing 3845#*973#, mo...
CVEs:CVE-2013-3666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| optimus_g_e973 | affected | lg | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.