Vulnerabilities > Google > Chrome > 4.0.249.76

DATE CVE VULNERABILITY TITLE RISK
2011-03-25 CVE-2011-1291 Classic Buffer Overflow vulnerability in Google Chrome
Google Chrome before 10.0.648.204 does not properly handle base strings, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "buffer error."
network
low complexity
google CWE-120
7.5
2011-03-20 CVE-2011-1465 Unspecified vulnerability in Google Chrome
The SPDY implementation in net/http/http_network_transaction.cc in Google Chrome before 11.0.696.14 drains the bodies from SPDY responses, which might allow remote SPDY servers to cause a denial of service (application exit) by canceling a stream.
network
low complexity
google
5.0
2011-03-15 CVE-2011-0609 Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
local
low complexity
adobe opensuse suse google
7.8
2011-03-11 CVE-2011-1413 Multiple Security vulnerability in Google Chrome prior to 10.0.648.127
Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X server, which allows remote attackers to cause a denial of service (application crash) via vectors involving long messages.
network
low complexity
google
5.0
2011-03-11 CVE-2011-1286 Multiple Security vulnerability in Google Chrome
Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger incorrect access to memory.
network
low complexity
google
7.5
2011-03-11 CVE-2011-1285 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
The regular-expression functionality in Google Chrome before 10.0.648.127 does not properly implement reentrancy, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
network
low complexity
google CWE-119
7.5
2011-03-11 CVE-2011-1204 Improper Input Validation vulnerability in Google Chrome
Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
network
google apple CWE-20
6.8
2011-03-11 CVE-2011-1203 Multiple Security vulnerability in Google Chrome
Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
network
low complexity
google apple
7.5
2011-03-11 CVE-2011-1202 Information Exposure vulnerability in Google Chrome
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
network
low complexity
google xmlsoft CWE-200
4.3
2011-03-11 CVE-2011-1201 Multiple Security vulnerability in Google Chrome
The context implementation in WebKit, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
network
low complexity
google
7.5