VulnerabilityModified
CVE-2011-3055
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
MEDIUM 4.3EPSS 1.69%
Does this matter?
Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.
Description
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- google/chrome · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=117736Exploit, Vendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlRelease Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/48512Not Applicable
- http://secunia.com/advisories/48527Not Applicable
- http://security.gentoo.org/glsa/glsa-201203-19.xmlThird Party Advisory
- http://www.securityfocus.com/bid/52674Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026841Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74215Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15033Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=117736Exploit, Vendor Advisory
- http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlRelease Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/48512Not Applicable
- http://secunia.com/advisories/48527Not Applicable
- http://security.gentoo.org/glsa/glsa-201203-19.xmlThird Party Advisory
- http://www.securityfocus.com/bid/52674Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026841Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74215Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15033Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.