CVE Vulnerabilities

CVE-2013-2866

Published: Jun 19, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machines physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

Affected Software

NameVendorStart VersionEnd Version
ChromeGoogle*27.0.1453.115 (including)
ChromeGoogle27.0.1453.0 (including)27.0.1453.0 (including)
ChromeGoogle27.0.1453.1 (including)27.0.1453.1 (including)
ChromeGoogle27.0.1453.2 (including)27.0.1453.2 (including)
ChromeGoogle27.0.1453.3 (including)27.0.1453.3 (including)
ChromeGoogle27.0.1453.4 (including)27.0.1453.4 (including)
ChromeGoogle27.0.1453.5 (including)27.0.1453.5 (including)
ChromeGoogle27.0.1453.6 (including)27.0.1453.6 (including)
ChromeGoogle27.0.1453.7 (including)27.0.1453.7 (including)
ChromeGoogle27.0.1453.8 (including)27.0.1453.8 (including)
ChromeGoogle27.0.1453.9 (including)27.0.1453.9 (including)
ChromeGoogle27.0.1453.10 (including)27.0.1453.10 (including)
ChromeGoogle27.0.1453.11 (including)27.0.1453.11 (including)
ChromeGoogle27.0.1453.12 (including)27.0.1453.12 (including)
ChromeGoogle27.0.1453.13 (including)27.0.1453.13 (including)
ChromeGoogle27.0.1453.15 (including)27.0.1453.15 (including)
ChromeGoogle27.0.1453.34 (including)27.0.1453.34 (including)
ChromeGoogle27.0.1453.35 (including)27.0.1453.35 (including)
ChromeGoogle27.0.1453.36 (including)27.0.1453.36 (including)
ChromeGoogle27.0.1453.37 (including)27.0.1453.37 (including)
ChromeGoogle27.0.1453.38 (including)27.0.1453.38 (including)
ChromeGoogle27.0.1453.39 (including)27.0.1453.39 (including)
ChromeGoogle27.0.1453.40 (including)27.0.1453.40 (including)
ChromeGoogle27.0.1453.41 (including)27.0.1453.41 (including)
ChromeGoogle27.0.1453.42 (including)27.0.1453.42 (including)
ChromeGoogle27.0.1453.43 (including)27.0.1453.43 (including)
ChromeGoogle27.0.1453.44 (including)27.0.1453.44 (including)
ChromeGoogle27.0.1453.45 (including)27.0.1453.45 (including)
ChromeGoogle27.0.1453.46 (including)27.0.1453.46 (including)
ChromeGoogle27.0.1453.47 (including)27.0.1453.47 (including)
ChromeGoogle27.0.1453.49 (including)27.0.1453.49 (including)
ChromeGoogle27.0.1453.50 (including)27.0.1453.50 (including)
ChromeGoogle27.0.1453.51 (including)27.0.1453.51 (including)
ChromeGoogle27.0.1453.52 (including)27.0.1453.52 (including)
ChromeGoogle27.0.1453.54 (including)27.0.1453.54 (including)
ChromeGoogle27.0.1453.55 (including)27.0.1453.55 (including)
ChromeGoogle27.0.1453.56 (including)27.0.1453.56 (including)
ChromeGoogle27.0.1453.57 (including)27.0.1453.57 (including)
ChromeGoogle27.0.1453.58 (including)27.0.1453.58 (including)
ChromeGoogle27.0.1453.59 (including)27.0.1453.59 (including)
ChromeGoogle27.0.1453.60 (including)27.0.1453.60 (including)
ChromeGoogle27.0.1453.61 (including)27.0.1453.61 (including)
ChromeGoogle27.0.1453.62 (including)27.0.1453.62 (including)
ChromeGoogle27.0.1453.63 (including)27.0.1453.63 (including)
ChromeGoogle27.0.1453.64 (including)27.0.1453.64 (including)
ChromeGoogle27.0.1453.65 (including)27.0.1453.65 (including)
ChromeGoogle27.0.1453.66 (including)27.0.1453.66 (including)
ChromeGoogle27.0.1453.67 (including)27.0.1453.67 (including)
ChromeGoogle27.0.1453.68 (including)27.0.1453.68 (including)
ChromeGoogle27.0.1453.69 (including)27.0.1453.69 (including)
ChromeGoogle27.0.1453.70 (including)27.0.1453.70 (including)
ChromeGoogle27.0.1453.71 (including)27.0.1453.71 (including)
ChromeGoogle27.0.1453.72 (including)27.0.1453.72 (including)
ChromeGoogle27.0.1453.73 (including)27.0.1453.73 (including)
ChromeGoogle27.0.1453.74 (including)27.0.1453.74 (including)
ChromeGoogle27.0.1453.75 (including)27.0.1453.75 (including)
ChromeGoogle27.0.1453.76 (including)27.0.1453.76 (including)
ChromeGoogle27.0.1453.77 (including)27.0.1453.77 (including)
ChromeGoogle27.0.1453.78 (including)27.0.1453.78 (including)
ChromeGoogle27.0.1453.79 (including)27.0.1453.79 (including)
ChromeGoogle27.0.1453.80 (including)27.0.1453.80 (including)
ChromeGoogle27.0.1453.81 (including)27.0.1453.81 (including)
ChromeGoogle27.0.1453.82 (including)27.0.1453.82 (including)
ChromeGoogle27.0.1453.83 (including)27.0.1453.83 (including)
ChromeGoogle27.0.1453.84 (including)27.0.1453.84 (including)
ChromeGoogle27.0.1453.85 (including)27.0.1453.85 (including)
ChromeGoogle27.0.1453.86 (including)27.0.1453.86 (including)
ChromeGoogle27.0.1453.87 (including)27.0.1453.87 (including)
ChromeGoogle27.0.1453.88 (including)27.0.1453.88 (including)
ChromeGoogle27.0.1453.89 (including)27.0.1453.89 (including)
ChromeGoogle27.0.1453.90 (including)27.0.1453.90 (including)
ChromeGoogle27.0.1453.91 (including)27.0.1453.91 (including)
ChromeGoogle27.0.1453.93 (including)27.0.1453.93 (including)
ChromeGoogle27.0.1453.94 (including)27.0.1453.94 (including)
ChromeGoogle27.0.1453.102 (including)27.0.1453.102 (including)
ChromeGoogle27.0.1453.103 (including)27.0.1453.103 (including)
ChromeGoogle27.0.1453.104 (including)27.0.1453.104 (including)
ChromeGoogle27.0.1453.105 (including)27.0.1453.105 (including)
ChromeGoogle27.0.1453.106 (including)27.0.1453.106 (including)
ChromeGoogle27.0.1453.107 (including)27.0.1453.107 (including)
ChromeGoogle27.0.1453.108 (including)27.0.1453.108 (including)
ChromeGoogle27.0.1453.109 (including)27.0.1453.109 (including)
ChromeGoogle27.0.1453.110 (including)27.0.1453.110 (including)
ChromeGoogle27.0.1453.111 (including)27.0.1453.111 (including)
ChromeGoogle27.0.1453.112 (including)27.0.1453.112 (including)
ChromeGoogle27.0.1453.113 (including)27.0.1453.113 (including)
ChromeGoogle27.0.1453.114 (including)27.0.1453.114 (including)
Chromium-browserUbuntuupstream*

References