VulnerabilityModified
CVE-2011-2861
Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via a crafted document that triggers an incorrect read operation.
MEDIUM 6.8EPSS 1.47%
Does this matter?
Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via a crafted document that triggers an incorrect read operation.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://code.google.com/p/chromium/issues/detail?id=93596
- http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_16.html
- http://osvdb.org/75563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69888
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14677
- http://code.google.com/p/chromium/issues/detail?id=93596
- http://googlechromereleases.blogspot.com/2011/09/stable-channel-update_16.html
- http://osvdb.org/75563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69888
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14677
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.