Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.805935
Categoría:General
Título:Google Chrome Multiple Vulnerabilities-01 July15 (Mac OS X)
Resumen:The host is installed with Google Chrome; and is prone to multiple vulnerabilities.
Descripción:Summary:
The host is installed with Google Chrome
and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Multiple heap based buffer-overflow in pdfium.

- An error which allows executable files to run immediately after download.

- A use-after-free error in IndexedDB.

- A memory corruption error in skia.

- An error allowing content security policy (CSP) bypass.

- A use-after-free error in pdfium.

- A heap based buffer-overflow in expat.

- A use-after-free error in blink.

- Universal cross-site scripting (UXSS) error in blink.

- An error in cascading style sheets (CSS) allowing to bypass same origin
policy.

- Uninitialized memory read error in ICU.

- A use-after-free error related to unexpected GPU process termination.

- A use-after-free error in accessibility.

- An error leading to URL spoofing using pdf files.

- An error leading to information leak in XSS auditor.

- An error allowing spell checking dictionaries to be fetched over HTTP.

- The regular-expression implementation in Google V8 mishandles interrupts.

- Various other unspecified errors.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to bypass security restrictions, cause a denial of service condition
or potentially execute arbitrary code, conduct spoofing attack, gain sensitive
information and other unspecified impacts.

Affected Software/OS:
Google Chrome version prior to
44.0.2403.89 on Mac OS X.

Solution:
Upgrade to Google Chrome version
44.0.2403.89 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: BugTraq ID: 75973
BugTraq ID: 76007
Common Vulnerability Exposure (CVE) ID: CVE-2015-1271
http://www.securityfocus.com/bid/75973
Debian Security Information: DSA-3315 (Google Search)
http://www.debian.org/security/2015/dsa-3315
https://security.gentoo.org/glsa/201603-09
RedHat Security Advisories: RHSA-2015:1499
http://rhn.redhat.com/errata/RHSA-2015-1499.html
http://www.securitytracker.com/id/1033031
SuSE Security Announcement: openSUSE-SU-2015:1287 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-1273
Common Vulnerability Exposure (CVE) ID: CVE-2015-1274
Common Vulnerability Exposure (CVE) ID: CVE-2015-1276
Common Vulnerability Exposure (CVE) ID: CVE-2015-1279
Common Vulnerability Exposure (CVE) ID: CVE-2015-1280
Common Vulnerability Exposure (CVE) ID: CVE-2015-1281
Common Vulnerability Exposure (CVE) ID: CVE-2015-1282
Common Vulnerability Exposure (CVE) ID: CVE-2015-1283
Debian Security Information: DSA-3318 (Google Search)
http://www.debian.org/security/2015/dsa-3318
https://security.gentoo.org/glsa/201701-21
SuSE Security Announcement: SUSE-SU-2016:1508 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00006.html
SuSE Security Announcement: SUSE-SU-2016:1512 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00007.html
SuSE Security Announcement: openSUSE-SU-2016:1441 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00064.html
SuSE Security Announcement: openSUSE-SU-2016:1523 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00010.html
http://www.ubuntu.com/usn/USN-2726-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-1284
Common Vulnerability Exposure (CVE) ID: CVE-2015-1286
Common Vulnerability Exposure (CVE) ID: CVE-2015-1287
Common Vulnerability Exposure (CVE) ID: CVE-2015-1270
Debian Security Information: DSA-3360 (Google Search)
http://www.debian.org/security/2015/dsa-3360
http://www.ubuntu.com/usn/USN-2740-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-1272
https://codereview.chromium.org/867553003/
Common Vulnerability Exposure (CVE) ID: CVE-2015-1277
Common Vulnerability Exposure (CVE) ID: CVE-2015-1278
Common Vulnerability Exposure (CVE) ID: CVE-2015-1285
Common Vulnerability Exposure (CVE) ID: CVE-2015-1288
Common Vulnerability Exposure (CVE) ID: CVE-2015-1289
Common Vulnerability Exposure (CVE) ID: CVE-2015-5605
http://www.securityfocus.com/bid/76007
Common Vulnerability Exposure (CVE) ID: CVE-2015-1290
http://www.nsfocus.net/index.php?act=advisory&do=view&adv_id=80
SuSE Security Announcement: openSUSE-SU-2015:2368 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-12/msg00116.html
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.