4.3
CVSSv2

CVE-2013-6628

Published: 13/11/2013 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome prior to 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 31.0.1650.45

google chrome 31.0.1650.44

google chrome 31.0.1650.36

google chrome 31.0.1650.35

google chrome 31.0.1650.27

google chrome 31.0.1650.26

google chrome 31.0.1650.43

google chrome 31.0.1650.42

google chrome 31.0.1650.34

google chrome 31.0.1650.33

google chrome 31.0.1650.32

google chrome 31.0.1650.25

google chrome 31.0.1650.23

google chrome 31.0.1650.15

google chrome 31.0.1650.14

google chrome 31.0.1650.6

google chrome 31.0.1650.5

google chrome 31.0.1650.41

google chrome 31.0.1650.39

google chrome 31.0.1650.31

google chrome 31.0.1650.30

google chrome 31.0.1650.22

google chrome 31.0.1650.20

google chrome 31.0.1650.13

google chrome 31.0.1650.12

google chrome 31.0.1650.4

google chrome 31.0.1650.3

google chrome 31.0.1650.17

google chrome 31.0.1650.16

google chrome 31.0.1650.9

google chrome 31.0.1650.8

google chrome 31.0.1650.7

google chrome

google chrome 31.0.1650.46

google chrome 31.0.1650.38

google chrome 31.0.1650.37

google chrome 31.0.1650.29

google chrome 31.0.1650.28

google chrome 31.0.1650.19

google chrome 31.0.1650.18

google chrome 31.0.1650.11

google chrome 31.0.1650.10

google chrome 31.0.1650.2

google chrome 31.0.1650.0

Vendor Advisories

Several vulnerabilities have been discovered in the chromium web browser CVE-2013-2931 The chrome 31 development team found various issues from internal fuzzing, audits, and other studies CVE-2013-6621 Khalil Zhani discovered a use-after-free issue in speech input handling CVE-2013-6622 cloudfuzzer discovered a use-after-fre ...