CVE-2013-0911
published 2013-03-05CVE-2013-0911: Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.
PriorityP434high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.27%
66.9th percentile
Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.
Affected
106 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 25.0.1364.126 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mwx-cmcr-9jjp: Directory traversal vulnerability in Google Chrome before 25
ghsa_unreviewed·2022-05-17
CVE-2013-0911 [HIGH] CWE-22 GHSA-5mwx-cmcr-9jjp: Directory traversal vulnerability in Google Chrome before 25
Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.
Red Hat
kernel: fs: filp leak on ro filesystem
vendor_redhat·2013-06-17·CVSS 4.7
CVE-2013-2188 [MEDIUM] kernel: fs: filp leak on ro filesystem
kernel: fs: filp leak on ro filesystem
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux MRG 2.
This issue was addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0911 (https://rhn.redhat.com/errata/RHSA-2013-0911.html).
Upstream is not affected.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affec
Red Hat
kernel: kvm: missing check in kvm_set_memory_region()
vendor_redhat·2013-06-10·CVSS 7.8
CVE-2013-1943 [HIGH] CWE-119 kernel: kvm: missing check in kvm_set_memory_region()
kernel: kvm: missing check in kvm_set_memory_region()
The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/kvm_main.c.
Statement: This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise MRG 2.
Future kvm updates for Red Hat Enterprise Linux 5 may address this flaw.
This issue was addresses in Red Hat Enterprise Linux 6 via RHSA-2013:0911 (https://rhn.redhat.com/errata/RHSA-2013-0911.html).
Please note that unlike Red Hat Enterprise Linux 6, where a local un
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_4.htmlhttps://code.google.com/p/chromium/issues/detail?id=172264https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16377http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_4.htmlhttps://code.google.com/p/chromium/issues/detail?id=172264https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16377
2013-03-05
Published