Vulnerabilities > CVE-2011-2819
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.
Vulnerable Configurations
Nessus
NASL family Windows NASL id SAFARI_5_1_1.NASL description The version of Safari installed on the remote Windows host is earlier than 5.1.1. Thus, it is potentially affected by numerous issues in the following components : - Safari - WebKit last seen 2020-06-01 modified 2020-06-02 plugin id 56483 published 2011-10-13 reporter This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/56483 title Safari < 5.1.1 Multiple Vulnerabilities NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_6887828F022911E0B84D00262D5ED8EE.NASL description Google Chrome Releases reports : Fixed in 15.0.874.121 : [103259] High CVE-2011-3900: Out-of-bounds write in v8. Credit to Christian Holler. Fixed in 15.0.874.120 : [100465] High CVE-2011-3892: Double free in Theora decoder. Credit to Aki Helin of OUSPG. [100492] [100543] Medium CVE-2011-3893: Out of bounds reads in MKV and Vorbis media handlers. Credit to Aki Helin of OUSPG. [101172] High CVE-2011-3894: Memory corruption regression in VP8 decoding. Credit to Andrew Scherkus of the Chromium development community. [101458] High CVE-2011-3895: Heap overflow in Vorbis decoder. Credit to Aki Helin of OUSPG. [101624] High CVE-2011-3896: Buffer overflow in shader variable mapping. Credit to Ken last seen 2020-06-01 modified 2020-06-02 plugin id 51069 published 2010-12-08 reporter This script is Copyright (C) 2010-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/51069 title FreeBSD : chromium -- multiple vulnerabilities (6887828f-0229-11e0-b84d-00262d5ed8ee) NASL family Windows NASL id GOOGLE_CHROME_13_0_782_107.NASL description The version of Google Chrome installed on the remote host is earlier than 13.0.782.107. As such, it is potentially affected by several vulnerabilities : - An unspecified error exists related to extension installation and confirmation dialogs. (Issue #75821) - A stale pointer issue exists related to bad line box tracking and rendering. (Issue #78841) - A security bypass issue exists related to file download prompts. (Issue #79266) - A string handling issue exists related to the HTTP basic authentication dialog box. (Issue #79426) - Developer mode NPAPI extensions do not always prompt a user before installation. (Issue #83273) - A local, unspecified path disclosure issue exists and is related to the GL log. (Issue #83841) - Extensions last seen 2020-06-01 modified 2020-06-02 plugin id 55765 published 2011-08-04 reporter This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/55765 title Google Chrome < 13.0.782.107 Multiple Vulnerabilities NASL family MacOS X Local Security Checks NASL id MACOSX_SAFARI5_1_1.NASL description The version of Apple Safari installed on the remote Mac OS X host is earlier than 5.1.1. Thus, it is potentially affected by numerous issues in the following components : - Safari - WebKit last seen 2020-06-01 modified 2020-06-02 plugin id 56482 published 2011-10-13 reporter This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/56482 title Mac OS X : Apple Safari < 5.1.1
Oval
accepted | 2014-04-07T04:00:25.102-04:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
description | Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:13716 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2011-12-09T10:47:12.000-05:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
title | Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
version | 52 |
References
- http://code.google.com/p/chromium/issues/detail?id=90222
- http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00004.html
- http://osvdb.org/74258
- http://support.apple.com/kb/HT4999
- http://support.apple.com/kb/HT5000
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68969
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13716
- http://code.google.com/p/chromium/issues/detail?id=90222
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13716
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68969
- http://support.apple.com/kb/HT5000
- http://support.apple.com/kb/HT4999
- http://osvdb.org/74258
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00004.html
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html
- http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html