VulnerabilityModified
CVE-2011-2841
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
MEDIUM 6.8EPSS 3.69%
Does this matter?
Lower severity and a low EPSS score (3.69%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.69% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://code.google.com/p/chromium/issues/detail?id=78639
- http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_16.html
- http://osvdb.org/75541
- http://securityreason.com/securityalert/8411
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69868
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14019
- https://www.exploit-db.com/exploits/17929/
- http://code.google.com/p/chromium/issues/detail?id=78639
- http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_16.html
- http://osvdb.org/75541
- http://securityreason.com/securityalert/8411
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69868
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14019
- https://www.exploit-db.com/exploits/17929/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.