CVE-2011-3046
published 2012-03-09CVE-2011-3046: The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.82%
91.0th percentile
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 5.1.1 | 5.1.1 |
| apple | safari | < 5.1.7 | 5.1.7 |
| chrome | < 17.0.963.78 | 17.0.963.78 | |
| opensuse | opensuse | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2012-08-08
CVE-2011-3046 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
GHSA
GHSA-7jq2-gmmw-gv34: The extension subsystem in Google Chrome before 17
ghsa_unreviewed·2022-05-13
CVE-2011-3046 [HIGH] CWE-79 GHSA-7jq2-gmmw-gv34: The extension subsystem in Google Chrome before 17
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=117226http://code.google.com/p/chromium/issues/detail?id=117230http://googlechromereleases.blogspot.com/2012/03/chrome-stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlhttp://secunia.com/advisories/47292http://secunia.com/advisories/48321http://secunia.com/advisories/48419http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttp://support.apple.com/kb/HT5282http://www.securityfocus.com/bid/52369http://www.securitytracker.com/id?1026776http://www.zdnet.com/blog/security/cansecwest-pwnium-google-chrome-hacked-with-sandbox-bypass/10563https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14686https://plus.google.com/u/0/116651741222993143554/posts/5Eq5d9XgFqshttp://code.google.com/p/chromium/issues/detail?id=117226http://code.google.com/p/chromium/issues/detail?id=117230http://googlechromereleases.blogspot.com/2012/03/chrome-stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlhttp://secunia.com/advisories/47292http://secunia.com/advisories/48321http://secunia.com/advisories/48419http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttp://support.apple.com/kb/HT5282http://www.securityfocus.com/bid/52369http://www.securitytracker.com/id?1026776http://www.zdnet.com/blog/security/cansecwest-pwnium-google-chrome-hacked-with-sandbox-bypass/10563https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14686https://plus.google.com/u/0/116651741222993143554/posts/5Eq5d9XgFqs
2012-03-09
Published