CVE-2011-3056
published 2012-03-22CVE-2011-3056: Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.33%
68.1th percentile
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 5.1.1 | 5.1.1 |
| apple | safari | < 5.1.7 | 5.1.7 |
| chrome | < 17.0.963.83 | 17.0.963.83 | |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rjjp-92fx-h9v7: Google Chrome before 17
ghsa_unreviewed·2022-05-13
CVE-2011-3056 [MEDIUM] CWE-346 GHSA-rjjp-92fx-h9v7: Google Chrome before 17
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
Red Hat
Webkitgtk: google chrome update [21-March-2012]
vendor_redhat·2012-03-21·CVSS 6.8
CVE-2011-3056 [MEDIUM] Webkitgtk: google chrome update [21-March-2012]
Webkitgtk: google chrome update [21-March-2012]
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
Statement: Not Vulnerable. This issue does not affect the version of webkitgtk as shipped with Red Hat Enterprise Linux 6.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=117550http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlhttp://osvdb.org/80294http://osvdb.org/81794http://secunia.com/advisories/47292http://secunia.com/advisories/48512http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttp://support.apple.com/kb/HT5282http://www.securityfocus.com/bid/52674http://www.securitytracker.com/id?1026841https://exchange.xforce.ibmcloud.com/vulnerabilities/74216https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14962http://code.google.com/p/chromium/issues/detail?id=117550http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.htmlhttp://osvdb.org/80294http://osvdb.org/81794http://secunia.com/advisories/47292http://secunia.com/advisories/48512http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttp://support.apple.com/kb/HT5282http://www.securityfocus.com/bid/52674http://www.securitytracker.com/id?1026841https://exchange.xforce.ibmcloud.com/vulnerabilities/74216https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14962
2012-03-22
Published