CVE-2011-1189
published 2011-03-11CVE-2011-1189: Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attackers to cause a denial of service or possibly have unspecified…
PriorityP426high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.59%
73.3th percentile
Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 10.0.648.127 | 10.0.648.127 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-56j5-2vvr-cv2v: Google Chrome before 10
ghsa_unreviewed·2022-05-13
CVE-2011-1189 [HIGH] GHSA-56j5-2vvr-cv2v: Google Chrome before 10
Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
OSV
CVE-2011-1189: Google Chrome before 10
osv·2011-03-11·CVSS 7.5
CVE-2011-1189 [HIGH] CVE-2011-1189: Google Chrome before 10
Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
Red Hat
kernel: bluetooth: buffer overflow in l2cap config request
vendor_redhat·2011-06-24·CVSS 8.3
CVE-2011-2497 [HIGH] CWE-191 kernel: bluetooth: buffer overflow in l2cap config request
kernel: bluetooth: buffer overflow in l2cap config request
Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit 5dee9e7c that introduced this issue. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1189.html, and ht
Red Hat
kernel: /proc/PID/io infoleak
vendor_redhat·2011-06-21·CVSS 2.1
CVE-2011-2495 [LOW] kernel: /proc/PID/io infoleak
kernel: /proc/PID/io infoleak
fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1212.html, https://rhn.redhat.com/errata/RHSA-2011-1189.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future updates.
Package: kernel (
Red Hat
kernel: ext4: kernel panic when writing data to the last block of sparse file
vendor_redhat·2011-06-03·CVSS 4.9
CVE-2011-2695 [MEDIUM] kernel: ext4: kernel panic when writing data to the last block of sparse file
kernel: ext4: kernel panic when writing data to the last block of sparse file
Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest possible 32-bit unsigned integer.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1189.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for EXT4 filesystem.
Pa
Red Hat
kernel: ksm: race between ksmd and exiting task
vendor_redhat·2011-06-02·CVSS 4.0
CVE-2011-2183 [MEDIUM] kernel: ksm: race between ksmd and exiting task
kernel: ksm: race between ksmd and exiting task
Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted application.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, and Red Hat Enterprise MRG do not provide support for KSM (Kernel Samepage Merging). This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2011-1189.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Red Hat
kernel: nl80211: missing check for valid SSID size in scan operations
vendor_redhat·2011-05-18·CVSS 7.2
CVE-2011-2517 [HIGH] kernel: nl80211: missing check for valid SSID size in scan operations
kernel: nl80211: missing check for valid SSID size in scan operations
Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4 as it did not provide support for the Linux wireless LAN (802.11) configuration API. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1212.html, https://rhn.redhat.com/errata/RHSA-2011-1189.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: ker
Red Hat
kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace
vendor_redhat·2011-05-09·CVSS 1.9
CVE-2011-2492 [LOW] kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace
kernel: bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace
The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.
Statement: This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0927.html, https://rhn.redhat.com/errata/RHSA-2011-1189.html,
Red Hat
kernel: gfs2: make sure fallocate bytes is a multiple of blksize
vendor_redhat·2011-04-26·CVSS 4.9
CVE-2011-2689 [MEDIUM] kernel: gfs2: make sure fallocate bytes is a multiple of blksize
kernel: gfs2: make sure fallocate bytes is a multiple of blksize
The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and Red Hat Enterprise MRG as they did not provide support for the Global File System 2 (GFS2). This has been addressed in Red Hat Enterprise Linux 5 and 6 via https://rhn.redhat.com/errata/RHSA-2011-1065.html and https://rhn.redhat.com/errata/RHSA-2011-1189.html.
Package: kernel (Red Hat Enterprise Linux 4) -
Red Hat
kernel: proc: signedness issue in next_pidmap()
vendor_redhat·2011-04-13·CVSS 4.9
CVE-2011-1593 [MEDIUM] kernel: proc: signedness issue in next_pidmap()
kernel: proc: signedness issue in next_pidmap()
Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
Statement: This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0927.html, https://rhn.redhat.com/errata/RHSA-2011-1189.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, there
Red Hat
kernel signal spoofing issue
vendor_redhat·2011-03-23·CVSS 3.6
CVE-2011-1182 [LOW] kernel signal spoofing issue
kernel signal spoofing issue
kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
Statement: Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future updates. This was addressed in Red Hat Enterprise Linux 5 and 6 via https://rhn.redhat.com/errata/RHSA-2011-0927.html and https://rhn.redhat.com/errata/RHSA-2011-1189.html. A future kernel update in Red Hat Enterprise MRG may address this flaw.
Package: kernel-rt (Red Hat Enterprise MRG 1) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=70027http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.htmlhttp://www.securityfocus.com/bid/46785http://www.vupen.com/english/advisories/2011/0628https://exchange.xforce.ibmcloud.com/vulnerabilities/65953https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14370http://code.google.com/p/chromium/issues/detail?id=70027http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.htmlhttp://www.securityfocus.com/bid/46785http://www.vupen.com/english/advisories/2011/0628https://exchange.xforce.ibmcloud.com/vulnerabilities/65953https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14370
2011-03-11
Published