Disclosed Chromium Security Bugs

[MD audit] [clipboard] Type confusion possible in Linux clipboard implementation

#40078405Reporter: sc...@gmail.com
$0
1/11/2010

[MD audit] [plugins] Sandbox Violation: Raw pointer from renderer manipulated in plugin process

#40078383Reporter: js...@chromium.org
$0
1/9/2010

[MD audit] [IPC] problems calling resize() on vectors with no sanitization

#40078318Reporter: sc...@gmail.com
$0
12/30/2009

[MD audit] [RPC] Integer overflow in clipboard image deserialization

#40078309Reporter: sc...@gmail.com
$0
12/29/2009

[MD audit] [V8]: integer errors lead to dangerous crashes in memory allocators

#40078272Reporter: sc...@gmail.com
$0
12/22/2009

[MD audit] [Window Sandbox] PreProcessName() Race Condition

#40078074Reporter: cp...@chromium.org
$0
11/25/2009

[MD audit] [Window Sandbox] Integrity Level Race Condition

#40078073Reporter: cp...@chromium.org
$0
11/25/2009

Security: chrome.test.resetQuota extension API exposed to all extensions

#40051105Reporter: aa...@chromium.org
$0
1/1/1970

Security: CSP connect-src and script-src not enforced on workers

#40051580Reporter: de...@gmail.com
$0
1/1/1970

SkMask::computeImageSize() integer overflow

#40052094Reporter: sk...@chromium.org
$0
1/1/1970
Showing 9221-9230 of 13102 bugs