CVE-2011-0475
published 2011-01-14CVE-2011-0475: Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or…
PriorityP430critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.01%
78.7th percentile
Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a PDF document.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 8.0.552.237 | 8.0.552.237 | |
| chrome_os | < 8.0.552.344 | 8.0.552.344 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1187 CVE-2012-0475 Multiple flaws in Firefox 12 which do not affect firefox 10.0.4 ESR
bugzilla·2012-04-23·CVSS 5.0
CVE-2011-1187 [MEDIUM] CVE-2011-1187 CVE-2012-0475 Multiple flaws in Firefox 12 which do not affect firefox 10.0.4 ESR
CVE-2011-1187 CVE-2012-0475 Multiple flaws in Firefox 12 which do not affect firefox 10.0.4 ESR
Multiple flaws were fixed in Mozilla Firefox and Thunderbird 12, the flaws described below do however do not affect the version of Firefox 10.0.4 ESR and Thunderbird 10.0.4 shipped with Red Hat Enterprise Linux.
Security researcher Simone Fabiano reported that if a cross-site XHR or WebSocket is opened on a web server on a non-standard port for web traffic while using an IPv6 address, the browser will send an ambiguous origin headers if the IPv6 address contains at least 2 consecutive 16-bit fields of zeroes. If there is an origin access control list that uses IPv6 literals, this issue could be used to bypass these access controls on the server.
Reference:
http://www.mozilla.org/security/annou
Bugzilla
CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0074 [CRITICAL] CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)
CVE-2011-0074 Mozilla crash from several marquee elements (MFSA 2011-12)
A crash was found in the way Mozilla products display several marquee
elements. A malformed HTML document could cause the application to crash or
possible execute arbitrary code with the permissions of the user running
the application.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise
Bugzilla
CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0078 [CRITICAL] CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
An arbitrary memory write flaw was found in the way Mozilla products deal
with an out of memory (OOM) condition. If all memory is consumed, it is
possible for arbitrary data to written using array offsets.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise L
Bugzilla
CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0073 [CRITICAL] CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)
CVE-2011-0073 Mozilla dangling pointer flaw (MFSA 2011-13)
An arbitrary code execution flaw was found in Mozilla products via the
nsTreeSelection element. If a user executes malformed content, it could be
possible to execute arbitrary code with the permissions of the user.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-13.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Bugzilla
CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0077 [CRITICAL] CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)
CVE-2011-0077 Mozilla integer overflow in frameset spec (MFSA 2011-12)
An integer overflow flaw was found in how Mozilla handled the frameset tag.
Using large values for the rows and cols attributes could cause an integer
overflow, resulting in a heap based buffer overflow.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux
Bugzilla
CVE-2011-0081 Mozilla memory safety issue (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0081 [CRITICAL] CVE-2011-0081 Mozilla memory safety issue (MFSA 2011-12)
CVE-2011-0081 Mozilla memory safety issue (MFSA 2011-12)
Mozilla developers identified and fixed several memory safety bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these bugs showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Mozilla developer Scoobidiver reported a memory safety issue which affected
Firefox 4 and Firefox 3.6
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following product
Bugzilla
CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)
bugzilla·2011-04-28·CVSS 5.0
CVE-2011-0071 [MEDIUM] CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)
CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)
A directory traversal flaw was found in Firefox's resource:// protocol
handler. If a user processed malicious content, it could use this flaw to
gain access to arbitrary files on the user's system.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-16.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0070 [CRITICAL] CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)
CVE-2011-0070 Mozilla double free flaw (MFSA 2011-12)
A double free flaw was found in Firefox's handling of
application/http-index-format documents. A malformed HTTP response could
cause Firefox to execute arbitrary code with the permissions of the user
running Firefox.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 4
Via RHSA-2011:0471 https://rhn.redhat.com/errata/RHSA-2011-0471.html
Bugzilla
CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0075 [CRITICAL] CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)
CVE-2011-0075 Mozilla crash from bad iframe source (MFSA 2011-12)
Mozilla products will crash when parsing an iframe tag with a bad source
address. If malicious HTML content contains a certain source address in an
iframe tag, it will cause the browser to crash due to an invalid memory
read.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat
http://code.google.com/p/chromium/issues/detail?id=67100http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlhttp://osvdb.org/70458http://secunia.com/advisories/42951http://www.securityfocus.com/bid/45788http://www.srware.net/forum/viewtopic.php?f=18&t=2054https://exchange.xforce.ibmcloud.com/vulnerabilities/64666https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14606http://code.google.com/p/chromium/issues/detail?id=67100http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlhttp://osvdb.org/70458http://secunia.com/advisories/42951http://www.securityfocus.com/bid/45788http://www.srware.net/forum/viewtopic.php?f=18&t=2054https://exchange.xforce.ibmcloud.com/vulnerabilities/64666https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14606
2011-01-14
Published