Loading...
Loading...
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions via an inappropriate header.
March 5, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-6666
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.