CVE-2013-0925
published 2013-03-28CVE-2013-0925: Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension…
PriorityP427high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
0.79%
52.8th percentile
Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension, which has unspecified impact and remote attack vectors.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 26.0.1410.42 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2152 rhevm: spice service unquoted search path
bugzilla·2013-06-05·CVSS 7.2
CVE-2013-2152 [HIGH] CVE-2013-2152 rhevm: spice service unquoted search path
CVE-2013-2152 rhevm: spice service unquoted search path
An unquoted search path flaw was found in the way Spice service for Windows was installed into the system.
A local unprivileged user could use this flaw to increase their privileges.
References:
http://cwe.mitre.org/data/definitions/428.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Virtualization 3.2
Via RHSA-2013:0924 https://rhn.redhat.com/errata/RHSA-2013-0924.html
---
This issue has been addressed in following products:
RHEV Manager version 3.2
Via RHSA-2013:0925 https://rhn.redhat.com/errata/RHSA-2013-0925.html
Bugzilla
CVE-2013-2151 rhevm: rhev agent service unquoted search path
bugzilla·2013-06-05·CVSS 7.2
CVE-2013-2151 [HIGH] CVE-2013-2151 rhevm: rhev agent service unquoted search path
CVE-2013-2151 rhevm: rhev agent service unquoted search path
An unquoted search path flaw was found in the way RHEV Agent for Windows was installed into the system.
A local unprivileged user could use this flaw to increase their privileges.
References:
http://cwe.mitre.org/data/definitions/428.html
Discussion:
This issue has been addressed in following products:
RHEV Manager version 3.2
Via RHSA-2013:0925 https://rhn.redhat.com/errata/RHSA-2013-0925.html
http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_26.htmlhttps://code.google.com/p/chromium/issues/detail?id=168442https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16363http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_26.htmlhttps://code.google.com/p/chromium/issues/detail?id=168442https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16363
2013-03-28
Published