CVE-2011-3067
published 2012-04-05CVE-2011-3067: Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.31%
67.8th percentile
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 6.0 | 6.0 |
| apple | safari | < 6.0 | 6.0 |
| chrome | < 18.0.1025.151 | 18.0.1025.151 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2012-10-25
CVE-2011-3059 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2012-08-08
CVE-2011-3046 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
GHSA
GHSA-g4mm-pj52-rmhj: Google Chrome before 18
ghsa_unreviewed·2022-05-13
CVE-2011-3067 [MEDIUM] CWE-346 GHSA-g4mm-pj52-rmhj: Google Chrome before 18
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=117583http://googlechromereleases.blogspot.com/2012/04/stable-and-beta-channel-updates.htmlhttp://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://osvdb.org/81037http://secunia.com/advisories/48732http://secunia.com/advisories/48749http://security.gentoo.org/glsa/glsa-201204-03.xmlhttp://support.apple.com/kb/HT5400http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/52913http://www.securitytracker.com/id?1026892https://exchange.xforce.ibmcloud.com/vulnerabilities/74627https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15342http://code.google.com/p/chromium/issues/detail?id=117583http://googlechromereleases.blogspot.com/2012/04/stable-and-beta-channel-updates.htmlhttp://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://osvdb.org/81037http://secunia.com/advisories/48732http://secunia.com/advisories/48749http://security.gentoo.org/glsa/glsa-201204-03.xmlhttp://support.apple.com/kb/HT5400http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/52913http://www.securitytracker.com/id?1026892https://exchange.xforce.ibmcloud.com/vulnerabilities/74627https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15342
2012-04-05
Published