| CVE-2010-0656 |
medium |
— |
4.3 |
|
|
googleapple |
17y ago |
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows a… |
| CVE-2010-0655 |
critical |
— |
10.0 |
EXP |
|
google |
17y ago |
Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors i… |
| CVE-2010-0651 |
medium |
— |
4.3 |
|
|
applegoogle |
17y ago |
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME… |
| CVE-2010-0649 |
critical |
— |
9.3 |
|
|
google |
17y ago |
Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a deni… |
| CVE-2010-0647 |
critical |
— |
9.3 |
|
|
googleapple |
17y ago |
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a <ruby>><ta… |
| CVE-2010-0646 |
critical |
— |
10.0 |
|
|
google |
17y ago |
Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via craf… |
| CVE-2010-0645 |
critical |
— |
9.3 |
|
|
google |
17y ago |
Multiple integer overflows in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use … |
| CVE-2010-0644 |
medium |
— |
4.3 |
|
|
google |
17y ago |
Google Chrome before 4.0.249.89, when a SOCKS 5 proxy server is configured, sends DNS queries directly, which allows remote DNS servers to obtain potentially sensitive information about the identity … |
| CVE-2010-0643 |
medium |
— |
4.3 |
|
|
google |
17y ago |
Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive in… |
| CVE-2010-0556 |
medium |
— |
4.3 |
|
|
google |
17y ago |
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-a… |