CVE-2011-3024Improper Certificate Validation in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16
Latest updateMay 13

Description

Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application crash) via an empty X.509 certificate.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDgoogle/chrome< 17.0.963.56

Patches

🔴Vulnerability Details

2
GHSA
GHSA-557r-q6mf-6mfm: Google Chrome before 172022-05-13
OSV
CVE-2011-3024: Google Chrome before 172012-02-16
CVE-2011-3024 — Improper Certificate Validation | cvebase