CVE-2013-6652 PUBLISHED CVSS 7.5 HIGH

Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for .. (dot dot) sequences or (2) lack of use of the \\?\ protection mechanism.

EPSS 0.29% · 51.9th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.29%
51.9th percentile

Affected Products

VendorProductVersions
n/an/an/a
googlechrome0, 33.0.1750.0, 33.0.1750.1

Timeline

References

Open in Interactive Console →