Lucene search

K
nvd[email protected]NVD:CVE-2013-2900
HistoryAug 21, 2013 - 12:17 p.m.

CVE-2013-2900

2013-08-2112:17:56
CWE-22
web.nvd.nist.gov
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0.011

Percentile

84.5%

The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.

Affected configurations

Nvd
Node
debiandebian_linuxMatch7.0
Node
googlechromeRange29.0.1547.56
OR
googlechromeMatch29.0.1547.0
OR
googlechromeMatch29.0.1547.1
OR
googlechromeMatch29.0.1547.2
OR
googlechromeMatch29.0.1547.3
OR
googlechromeMatch29.0.1547.4
OR
googlechromeMatch29.0.1547.5
OR
googlechromeMatch29.0.1547.7
OR
googlechromeMatch29.0.1547.8
OR
googlechromeMatch29.0.1547.9
OR
googlechromeMatch29.0.1547.10
OR
googlechromeMatch29.0.1547.11
OR
googlechromeMatch29.0.1547.12
OR
googlechromeMatch29.0.1547.13
OR
googlechromeMatch29.0.1547.14
OR
googlechromeMatch29.0.1547.15
OR
googlechromeMatch29.0.1547.16
OR
googlechromeMatch29.0.1547.17
OR
googlechromeMatch29.0.1547.18
OR
googlechromeMatch29.0.1547.19
OR
googlechromeMatch29.0.1547.20
OR
googlechromeMatch29.0.1547.21
OR
googlechromeMatch29.0.1547.22
OR
googlechromeMatch29.0.1547.23
OR
googlechromeMatch29.0.1547.27
OR
googlechromeMatch29.0.1547.28
OR
googlechromeMatch29.0.1547.29
OR
googlechromeMatch29.0.1547.30
OR
googlechromeMatch29.0.1547.31
OR
googlechromeMatch29.0.1547.32
OR
googlechromeMatch29.0.1547.33
OR
googlechromeMatch29.0.1547.34
OR
googlechromeMatch29.0.1547.35
OR
googlechromeMatch29.0.1547.36
OR
googlechromeMatch29.0.1547.37
OR
googlechromeMatch29.0.1547.38
OR
googlechromeMatch29.0.1547.39
OR
googlechromeMatch29.0.1547.40
OR
googlechromeMatch29.0.1547.41
OR
googlechromeMatch29.0.1547.42
OR
googlechromeMatch29.0.1547.45
OR
googlechromeMatch29.0.1547.46
OR
googlechromeMatch29.0.1547.47
OR
googlechromeMatch29.0.1547.48
OR
googlechromeMatch29.0.1547.49
OR
googlechromeMatch29.0.1547.50
OR
googlechromeMatch29.0.1547.51
OR
googlechromeMatch29.0.1547.52
OR
googlechromeMatch29.0.1547.53
OR
googlechromeMatch29.0.1547.54
OR
googlechromeMatch29.0.1547.55
AND
microsoftwindows
VendorProductVersionCPE
debiandebian_linux7.0cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
googlechrome29.0.1547.0cpe:2.3:a:google:chrome:29.0.1547.0:*:*:*:*:*:*:*
googlechrome29.0.1547.1cpe:2.3:a:google:chrome:29.0.1547.1:*:*:*:*:*:*:*
googlechrome29.0.1547.2cpe:2.3:a:google:chrome:29.0.1547.2:*:*:*:*:*:*:*
googlechrome29.0.1547.3cpe:2.3:a:google:chrome:29.0.1547.3:*:*:*:*:*:*:*
googlechrome29.0.1547.4cpe:2.3:a:google:chrome:29.0.1547.4:*:*:*:*:*:*:*
googlechrome29.0.1547.5cpe:2.3:a:google:chrome:29.0.1547.5:*:*:*:*:*:*:*
googlechrome29.0.1547.7cpe:2.3:a:google:chrome:29.0.1547.7:*:*:*:*:*:*:*
googlechrome29.0.1547.8cpe:2.3:a:google:chrome:29.0.1547.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 531

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0.011

Percentile

84.5%