CVE-2011-3041
published 2012-03-05CVE-2011-3041: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.71%
74.7th percentile
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 6.0 | 6.0 |
| apple | itunes | < 10.7 | 10.7 |
| apple | safari | < 6.0 | 6.0 |
| chrome | < 17.0.963.65 | 17.0.963.65 | |
| opensuse | opensuse | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0911 zikula: XSS vulnerability in Users module
bugzilla·2011-02-09·CVSS 6.8
CVE-2011-0911 [MEDIUM] CVE-2011-0911 zikula: XSS vulnerability in Users module
CVE-2011-0911 zikula: XSS vulnerability in Users module
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0911 to
the following vulnerability:
Name: CVE-2011-0911
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0911
Assigned: 20110208
Reference: http://community.zikula.org/index.php?module=News&func=display&sid=3041&title=zikula-1.2.5-released
Cross-site scripting (XSS) vulnerability in the Users module in Zikula
before 1.2.5 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors. NOTE: it is possible that this overlaps
CVE-2011-0535.
Discussion:
Created zikula tracking bugs for this issue
Affects: fedora-all [bug 676457]
Affects: epel-all [bug 676458]
Bugzilla
CVE-2011-0535 zikula: CSRF vulnerability in Users module
bugzilla·2011-02-09·CVSS 6.8
CVE-2011-0535 [MEDIUM] CVE-2011-0535 zikula: CSRF vulnerability in Users module
CVE-2011-0535 zikula: CSRF vulnerability in Users module
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0535 to
the following vulnerability:
Name: CVE-2011-0535
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0535
Assigned: 20110120
Reference: http://seclists.org/fulldisclosure/2011/Feb/0
Reference: http://openwall.com/lists/oss-security/2011/02/01/1
Reference: http://openwall.com/lists/oss-security/2011/02/03/1
Reference: http://bl0g.yehg.net/2011/02/zikula-cms-124-cross-site-request.html
Reference: http://code.zikula.org/core12/browser/tags/Zikula-1.2.5/src/docs/CHANGELOG
Reference: http://community.zikula.org/index.php?module=News&func=display&sid=3041&title=zikula-1.2.5-released
Reference: http://www.osvdb.org/70751
Reference: http://secunia.com/advi
http://code.google.com/p/chromium/issues/detail?id=114068http://googlechromereleases.blogspot.com/2012/03/chrome-stable-update.htmlhttp://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlhttp://secunia.com/advisories/48265http://secunia.com/advisories/48419http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttp://support.apple.com/kb/HT5400http://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/52271http://www.securitytracker.com/id?1026759https://exchange.xforce.ibmcloud.com/vulnerabilities/73652https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14923http://code.google.com/p/chromium/issues/detail?id=114068http://googlechromereleases.blogspot.com/2012/03/chrome-stable-update.htmlhttp://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlhttp://secunia.com/advisories/48265http://secunia.com/advisories/48419http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttp://support.apple.com/kb/HT5400http://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/52271http://www.securitytracker.com/id?1026759https://exchange.xforce.ibmcloud.com/vulnerabilities/73652https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14923
2012-03-05
Published