Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71375
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: chromium
Summary:The remote host is missing an update to the system; as announced in the referenced advisory.
Description:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: chromium

CVE-2011-3083
browser/profiles/profile_impl_io_data.cc in Google Chrome before
19.0.1084.46 does not properly handle a malformed ftp URL in the SRC
attribute of a VIDEO element, which allows remote attackers to cause a
denial of service (NULL pointer dereference and application crash) via
a crafted web page.
CVE-2011-3084
Google Chrome before 19.0.1084.46 does not use a dedicated process for
the loading of links found on an internal page, which might allow
attackers to bypass intended sandbox restrictions via a crafted page.
CVE-2011-3085
The Autofill feature in Google Chrome before 19.0.1084.46 does not
properly restrict field values, which allows remote attackers to cause
a denial of service (UI corruption) and possibly conduct spoofing
attacks via vectors involving long values.
CVE-2011-3086
Use-after-free vulnerability in Google Chrome before 19.0.1084.46
allows remote attackers to cause a denial of service or possibly have
unspecified other impact via vectors involving a STYLE element.
CVE-2011-3087
Google Chrome before 19.0.1084.46 does not properly perform window
navigation, which has unspecified impact and remote attack vectors.
CVE-2011-3088
Google Chrome before 19.0.1084.46 does not properly draw hairlines,
which allows remote attackers to cause a denial of service
(out-of-bounds read) via unspecified vectors.
CVE-2011-3089
Use-after-free vulnerability in Google Chrome before 19.0.1084.46
allows remote attackers to cause a denial of service or possibly have
unspecified other impact via vectors involving tables.
CVE-2011-3090
Race condition in Google Chrome before 19.0.1084.46 allows remote
attackers to cause a denial of service or possibly have unspecified
other impact via vectors related to worker processes.

Text truncated. Please see the references for more information.

This VT has been deprecated and is therefore no longer functional.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3083
BugTraq ID: 53540
http://www.securityfocus.com/bid/53540
http://security.gentoo.org/glsa/glsa-201205-03.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15103
http://www.securitytracker.com/id?1027067
SuSE Security Announcement: openSUSE-SU-2012:0656 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00017.html
XForce ISS Database: google-chrome-video-dos(75588)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75588
Common Vulnerability Exposure (CVE) ID: CVE-2011-3084
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15223
SuSE Security Announcement: openSUSE-SU-2012:0993 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00009.html
XForce ISS Database: google-chrome-links-sec-bypass(75589)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75589
Common Vulnerability Exposure (CVE) ID: CVE-2011-3085
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15256
XForce ISS Database: google-autofilled-code-execution(75590)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75590
Common Vulnerability Exposure (CVE) ID: CVE-2011-3086
http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.html
http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.html
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15206
XForce ISS Database: chrome-window-code-execution(75591)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75591
Common Vulnerability Exposure (CVE) ID: CVE-2011-3087
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15567
XForce ISS Database: chrome-window-code-execution(75592)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75592
Common Vulnerability Exposure (CVE) ID: CVE-2011-3088
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15581
XForce ISS Database: chrome-hairline-code-execution(75593)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75593
Common Vulnerability Exposure (CVE) ID: CVE-2011-3089
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15474
XForce ISS Database: chrome-table-handling-code-execution(75594)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75594
Common Vulnerability Exposure (CVE) ID: CVE-2011-3090
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15605
XForce ISS Database: google-chrome-wrokers-code-exec(75595)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75595
Common Vulnerability Exposure (CVE) ID: CVE-2011-3091
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15196
XForce ISS Database: chrome-indexeddb-code-exec(75596)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75596
Common Vulnerability Exposure (CVE) ID: CVE-2011-3092
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15610
XForce ISS Database: chrome-v8regex-code-exec(75597)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75597
Common Vulnerability Exposure (CVE) ID: CVE-2011-3093
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15358
XForce ISS Database: chrome-glyph-handling-code-exec(75598)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75598
Common Vulnerability Exposure (CVE) ID: CVE-2011-3094
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15233
XForce ISS Database: chrome-tibetan-code-exec(75599)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75599
Common Vulnerability Exposure (CVE) ID: CVE-2011-3095
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15159
XForce ISS Database: chrome-ogg-container-code-exec(75600)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75600
Common Vulnerability Exposure (CVE) ID: CVE-2011-3096
XForce ISS Database: chrome-gtk-code-exec(75601)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75601
Common Vulnerability Exposure (CVE) ID: CVE-2011-3097
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15422
XForce ISS Database: chrome-sampled-functions-code-exec(75602)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75602
Common Vulnerability Exposure (CVE) ID: CVE-2011-3099
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15208
XForce ISS Database: chrome-corrupt-font-code-exec(75604)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75604
Common Vulnerability Exposure (CVE) ID: CVE-2011-3100
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15224
XForce ISS Database: chrome-dash-paths-code-exec(75605)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75605
CopyrightCopyright (C) 2012 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.