VulnerabilityModified
CVE-2011-3037
Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
MEDIUM 6.8EPSS 1.85%
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-704
- Affected
- google/chrome · opensuse/opensuse · apple/itunes · apple/safari · apple/iphone os
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=113439Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=114924Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=115028Vendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/chrome-stable-update.htmlRelease Notes, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlMailing List, Third Party Advisory
- http://osvdb.org/79796Broken Link
- http://secunia.com/advisories/48265Not Applicable
- http://secunia.com/advisories/48419Not Applicable
- http://secunia.com/advisories/48527Not Applicable
- http://security.gentoo.org/glsa/glsa-201203-19.xmlThird Party Advisory
- http://support.apple.com/kb/HT5400Third Party Advisory
- http://support.apple.com/kb/HT5485Third Party Advisory
- http://support.apple.com/kb/HT5503Broken Link
- http://www.securityfocus.com/bid/52271Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026759Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73648Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14397Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=113439Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=114924Vendor Advisory
- http://code.google.com/p/chromium/issues/detail?id=115028Vendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/chrome-stable-update.htmlRelease Notes, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlMailing List, Third Party Advisory
- http://osvdb.org/79796Broken Link
- http://secunia.com/advisories/48265Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.