CVE-2011-0471
published 2011-01-14CVE-2011-0471: The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote…
PriorityP430critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.41%
82.3th percentile
The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 8.0.552.237 | 8.0.552.237 | |
| chrome_os | < 8.0.552.344 | 8.0.552.344 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0065 Mozilla mChannel use after free (MFSA 2011-13)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0065 [CRITICAL] CVE-2011-0065 Mozilla mChannel use after free (MFSA 2011-13)
CVE-2011-0065 Mozilla mChannel use after free (MFSA 2011-13)
A use after free flaw was found in Firefox's mChannel object.
Malicious content could use this flaw to execute arbitrary code with
permissions of the user running Firefox.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-13.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0072 Mozilla use after free flaw (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0072 [CRITICAL] CVE-2011-0072 Mozilla use after free flaw (MFSA 2011-12)
CVE-2011-0072 Mozilla use after free flaw (MFSA 2011-12)
A use after free flaw was found in the way Firefox appended frame and
iframe elements to a DOM tree when the NoScript add-on was enabled. If a
user processes malicious HTML content it could result in arbitrary code
execution with the permissions of the user.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0066 Mozilla mObserverList use after free (MFSA 2011-13)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0066 [CRITICAL] CVE-2011-0066 Mozilla mObserverList use after free (MFSA 2011-13)
CVE-2011-0066 Mozilla mObserverList use after free (MFSA 2011-13)
A use after free flaw was found in Firefox's mObserverList object.
Malicious content could use this flaw to execute arbitrary code with
permissions of the user running Firefox.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-13.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0069 Mozilla javascript crash (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0069 [CRITICAL] CVE-2011-0069 Mozilla javascript crash (MFSA 2011-12)
CVE-2011-0069 Mozilla javascript crash (MFSA 2011-12)
A flaw was found in the way Firefox handles certain JavaScript cross domain
requests. If malicious content generates a large number of cross domain
JavaScript requests it could cause Firefox to execute arbitrary code with
permissions of the user running Firefox.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)
bugzilla·2011-04-28·CVSS 5.0
CVE-2011-0071 [MEDIUM] CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)
CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)
A directory traversal flaw was found in Firefox's resource:// protocol
handler. If a user processed malicious content, it could use this flaw to
gain access to arbitrary files on the user's system.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-16.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0067 Mozilla untrusted events can trigger autocomplete popup (MFSA 2011-14)
bugzilla·2011-04-28·CVSS 5.0
CVE-2011-0067 [MEDIUM] CVE-2011-0067 Mozilla untrusted events can trigger autocomplete popup (MFSA 2011-14)
CVE-2011-0067 Mozilla untrusted events can trigger autocomplete popup (MFSA 2011-14)
A flaw was found in the way Firefox displays the autocomplete popup.
Malicious content could use this flaw to steal form history information.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-14.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0070 [CRITICAL] CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)
CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)
A double free flaw was found in Firefox's handling of
application/http-index-format documents. A malformed HTTP response could
cause Firefox to execute arbitrary code with the permissions of the user
running Firefox.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
http://code.google.com/p/chromium/issues/detail?id=65764http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlhttp://osvdb.org/70454http://secunia.com/advisories/42951http://www.securityfocus.com/bid/45788http://www.srware.net/forum/viewtopic.php?f=18&t=2054https://exchange.xforce.ibmcloud.com/vulnerabilities/64662https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13710http://code.google.com/p/chromium/issues/detail?id=65764http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlhttp://osvdb.org/70454http://secunia.com/advisories/42951http://www.securityfocus.com/bid/45788http://www.srware.net/forum/viewtopic.php?f=18&t=2054https://exchange.xforce.ibmcloud.com/vulnerabilities/64662https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13710
2011-01-14
Published