CVE-2013-2900
published 2013-08-21CVE-2013-2900: The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.55%
72.6th percentile
The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 29.0.1547.56 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Qualys
Patch Tuesday Risk Elimination with Agent Sara
blogs_qualys·2025-09-11
Patch Tuesday Risk Elimination with Agent Sara
## Table of Contents
Introduction
How Agent Sara Works
Agent Saras Role in Tuesday Patching
When Patches Arent Available, MTTR Rises
## Introduction
Risk elimination is the goal of any vulnerability management program. It is typically achieved through a combination of patching and scripting solutions. SecOps teams usually prioritize vulnerabilities and forward them to IT teams for remediation. However, the real challenge lies in deciding what to fix first and mapping the right patches or identifying vendor-provided fixes when patches are not yet available or can’t be deployed due to operational risk.
The Mean Time to Remediation (MTTR) depends heavily on the time spent prioritizing vulnerabilities, mapping the right patches, deploying them, or researching appropriate fixes when patc
Qualys
Qualys Agent Sara for Risk Elimination: Agentic AI Patching Guide | Qualys
blogs_qualys·2025-09-11
Qualys Agent Sara for Risk Elimination: Agentic AI Patching Guide | Qualys
#### Table of Contents
- Introduction
- How Agent Sara Works
- Agent Saras Role in Tuesday Patching
- When Patches Arent Available, MTTR Rises
## Introduction
Risk elimination is the goal of any vulnerability management program. It is typically achieved through a combination of patching and scripting solutions. SecOps teams usually prioritize vulnerabilities and forward them to IT teams for remediation. However, the real challenge lies in deciding what to fix first and mapping the right patches or identifying vendor-provided fixes when patches are not yet available or can’t be deployed due to operational risk.
The Mean Time to Remediation (MTTR) depends heavily on the time spent prioritizing vulnerabilities, mapping the right patches, deploying them, or researching appropriate fixes wh
Qualys
Mitigate High-Risk Vulnerabilities Using TruRisk | Qualys
blogs_qualys·2024-12-04·CVSS 7.5
CVE-2013-2900 [HIGH] Mitigate High-Risk Vulnerabilities Using TruRisk | Qualys
#### Table of Contents
- TruRisk Mitigate: A Flexible Approach to Vulnerability Management
- Managing CVE-2013-2900: WinVerifyTrust Signature Validation Vulnerability
- Mitigating CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
- Managing needrestart Vulnerabilities: Addressing Local Privilege Escalation (LPE) Risks
- Key Benefits of TruRisk Mitigate
- Strengthening Security with TruRisk Mitigate
In late 2024, organizations faced over 65 million detections from three critical vulnerabilities—CVE-2013-2900, CVE-2024-38122, and CVE-2024-30078—underscoring the urgent need for proactive vulnerability management. Adding to these challenges, the Qualys Threat Research Unit (TRU) uncovered five Local Privilege Escalation (LPE) vulnerabilities in November within the need
Qualys
Proactively Managing High-Risk Vulnerabilities with TruRisk Mitigate™
blogs_qualys·2024-12-04·CVSS 7.5
CVE-2013-2900 [HIGH] Proactively Managing High-Risk Vulnerabilities with TruRisk Mitigate™
## Table of Contents
TruRisk Mitigate: A Flexible Approach to Vulnerability Management
Managing CVE-2013-2900: WinVerifyTrust Signature Validation Vulnerability
Mitigating CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
Managing needrestart Vulnerabilities: Addressing Local Privilege Escalation (LPE) Risks
Key Benefits of TruRisk Mitigate
Strengthening Security with TruRisk Mitigate
In late 2024, organizations faced over 65 million detections from three critical vulnerabilities—CVE-2013-2900, CVE-2024-38122, and CVE-2024-30078—underscoring the urgent need for proactive vulnerability management. Adding to these challenges, the Qualys Threat Research Unit (TRU) uncovered five Local Privilege Escalation (LPE) vulnerabilities in November within the needrestart u
http://crbug.com/181617http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.htmlhttp://www.debian.org/security/2013/dsa-2741https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381https://src.chromium.org/viewvc/chrome?revision=200603&view=revisionhttp://crbug.com/181617http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.htmlhttp://www.debian.org/security/2013/dsa-2741https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381https://src.chromium.org/viewvc/chrome?revision=200603&view=revision
2013-08-21
Published