Severity
6.8MEDIUMNVD
EPSS
2.4%
top 14.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMay 13

Description

Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDgoogle/chrome< 18.0.1025.142
NVDmozilla/firefox< 10.0.4+1

🔴Vulnerability Details

2
GHSA
GHSA-fr3j-gxg3-m435: Off-by-one error in the OpenType Sanitizer in Google Chrome before 182022-05-13
CVEList
CVE-2011-3062: Off-by-one error in the OpenType Sanitizer in Google Chrome before 182012-03-30

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2012-05-04
Ubuntu
ubufox update2012-04-27
Ubuntu
Firefox vulnerabilities2012-04-27
Red Hat
Mozilla: Off-by-one error in OpenType Sanitizer (MFSA 2012-31)2012-04-24

💬Community

1
Bugzilla
CVE-2011-3062 Mozilla: Off-by-one error in OpenType Sanitizer (MFSA 2012-31)2012-04-22
CVE-2011-3062 — Incorrect Calculation in Google Chrome | cvebase