VulnerabilityModified
CVE-2011-3054
The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
MEDIUM 4.3EPSS 1.81%
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- google/chrome · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=117418Vendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlRelease Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlMailing List, Third Party Advisory
- http://osvdb.org/80292Broken Link
- http://secunia.com/advisories/48512Not Applicable
- http://secunia.com/advisories/48527Not Applicable
- http://security.gentoo.org/glsa/glsa-201203-19.xmlThird Party Advisory
- http://www.securityfocus.com/bid/52674Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026841Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74214Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=117418Vendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlRelease Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlMailing List, Third Party Advisory
- http://osvdb.org/80292Broken Link
- http://secunia.com/advisories/48512Not Applicable
- http://secunia.com/advisories/48527Not Applicable
- http://security.gentoo.org/glsa/glsa-201203-19.xmlThird Party Advisory
- http://www.securityfocus.com/bid/52674Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026841Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74214Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.