Google Chrome < 26.0.1410.43 Multiple Vulnerabilities

Medium Nessus Plugin ID 65691


The remote host contains a web browser that is affected by multiple vulnerabilities.


The version of Google Chrome installed on the remote host is a version prior to 26.0.1410.43 and is, therefore, affected by the following vulnerabilities :

- Use-after-free errors exist related to 'Web Audio' and the extension bookmarks API. (CVE-2013-0916, CVE-2013-0920)

- An out-of-bounds read error exists related to the URL loader. (CVE-2013-0917)

- An unspecified error exists related to 'drag and drop' actions and the developer tools. (CVE-2013-0918)

- An unspecified error exists related to website process isolation. (CVE-2013-0921)

- An error exists related to HTTP basic authentication and brute-force attacks. (CVE-2013-0922)

- A memory safety issue exists related to the 'USB Apps' API. (CVE-2013-0923)

- A permissions error exists related to extensions API and file permissions. (CVE-2013-0924)

- URLs can be leaked to extensions even if the extension does not have the 'tabs' permission. (CVE-2013-0925)

- An error exists related to 'active tags' and the paste action that has unspecified impact. (CVE-2013-0926)


Upgrade to Google Chrome 26.0.1410.43 or later.

See Also

Plugin Details

Severity: Medium

ID: 65691

File Name: google_chrome_26_0_1410_43.nasl

Version: $Revision: 1.13 $

Type: local

Agent: windows

Family: Windows

Published: 2013/03/26

Modified: 2014/10/03

Dependencies: 34196

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: SMB/Google_Chrome/Installed

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/03/26

Vulnerability Publication Date: 2013/03/26

Reference Information

CVE: CVE-2013-0916, CVE-2013-0917, CVE-2013-0918, CVE-2013-0920, CVE-2013-0921, CVE-2013-0922, CVE-2013-0923, CVE-2013-0924, CVE-2013-0925, CVE-2013-0926

BID: 58723, 58724, 58725, 58728, 58729, 58730, 58731, 58732, 58733, 58734

OSVDB: 91701, 91703, 91704, 91705, 91706, 91707, 91708, 91709, 91710, 91711