CVE-2011-1440Use After Free in Google Chrome

CWE-416Use After Free3 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
2.5%
top 14.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateMay 13

Description

Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDgoogle/chrome< 11.0.696.57
NVDapple/itunes< 10.5
NVDapple/safari< 5.1.1

Also affects: Debian Linux 6.0, 7.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-vvv3-884v-fqfw: Use-after-free vulnerability in Google Chrome before 112022-05-13

💬Community

1
Bugzilla
CVE-2011-3648 Mozilla: Universal XSS likely with MultiByte charset (MFSA 2011-47)2011-11-08