[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-2783

Date: (C)2011-08-02   (M)2017-09-22
 
CVSS Score: 6.4Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 4.9Authentication: NONE
 Confidentiality: NONE
 Integrity: PARTIAL
 Availability: PARTIAL











Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

Reference:
OSVDB-74233
google-chrome-npapi-code-execution(68945)
http://code.google.com/p/chromium/issues/detail?id=83273
http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html

CPE    1520
cpe:/a:google:chrome:11.0.660.0
cpe:/a:google:chrome:6.0.481.0
cpe:/a:google:chrome:13.0.782.10
cpe:/a:google:chrome:12.0.700.0
...
CWE    1
CWE-20
OVAL    4
oval:org.secpod.oval:def:1883
oval:org.secpod.oval:def:1884
oval:org.secpod.oval:def:1919
oval:org.secpod.oval:def:1948
...

© 2013 SecPod Technologies