CVE-2011-3068Use After Free in Google Chrome

CWE-416Use After Free4 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
1.6%
top 18.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 5
Latest updateMay 13

Description

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages4 packages

NVDgoogle/chrome< 18.0.1025.151
NVDapple/itunes< 10.7
NVDapple/safari< 6.0
NVDapple/iphone_os< 6.0

🔴Vulnerability Details

1
GHSA
GHSA-9475-c7p2-gfh5: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 182022-05-13

💥Exploits & PoCs

1
Exploit-DB
DVD X Player 5.5 - '.plf' Playlist Buffer Overflow (Metasploit)2011-09-01

📋Vendor Advisories

1
Ubuntu
WebKit vulnerabilities2012-08-08