cbcvebase.
CVE-2013-6666
published 2014-03-05

CVE-2013-6666: The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that…

PriorityP424medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.18%
64.5th percentile
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions via an inappropriate header.

Affected

106 ranges· showing 25
VendorProductVersion rangeFixed in
googlechrome<= 33.0.1750.144
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.