VulnerabilityModified
CVE-2011-0485
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."
HIGH 10.0EPSS 3.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.39% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/chrome os · google/chrome
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=68666Permissions Required
- http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlVendor Advisory
- http://osvdb.org/70468Broken Link
- http://secunia.com/advisories/42951Third Party Advisory
- http://www.securityfocus.com/bid/45788Third Party Advisory, VDB Entry
- http://www.srware.net/forum/viewtopic.php?f=18&t=2054Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64676Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14381Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=68666Permissions Required
- http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlVendor Advisory
- http://osvdb.org/70468Broken Link
- http://secunia.com/advisories/42951Third Party Advisory
- http://www.securityfocus.com/bid/45788Third Party Advisory, VDB Entry
- http://www.srware.net/forum/viewtopic.php?f=18&t=2054Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64676Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14381Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.