CVE-2011-0473
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with CANVAS elements, which allows remote attackers to cause a denial of service or possibly have…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with CANVAS elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- google/chrome os · google/chrome
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=66560Permissions Required
- http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlVendor Advisory
- http://osvdb.org/70456Broken Link
- http://secunia.com/advisories/42951Third Party Advisory
- http://www.securityfocus.com/bid/45788Third Party Advisory, VDB Entry
- http://www.srware.net/forum/viewtopic.php?f=18&t=2054Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64664Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14460Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=66560Permissions Required
- http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlVendor Advisory
- http://osvdb.org/70456Broken Link
- http://secunia.com/advisories/42951Third Party Advisory
- http://www.securityfocus.com/bid/45788Third Party Advisory, VDB Entry
- http://www.srware.net/forum/viewtopic.php?f=18&t=2054Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64664Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14460Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.