CVE-2011-3072
published 2012-04-05CVE-2011-3072: Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.19%
64.9th percentile
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 18.0.1025.151 | 18.0.1025.151 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vcv7-w6fc-r5xc: Google Chrome before 18
ghsa_unreviewed·2022-05-13
CVE-2011-3072 [MEDIUM] CWE-346 GHSA-vcv7-w6fc-r5xc: Google Chrome before 18
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.
Red Hat
Squid: Denial of service due internal error in string handling (SQUID-2010:3)
vendor_redhat·2010-09-03·CVSS 5.0
CVE-2010-3072 [MEDIUM] Squid: Denial of service due internal error in string handling (SQUID-2010:3)
Squid: Denial of service due internal error in string handling (SQUID-2010:3)
The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.
Statement: This issue did not affect the version of Squid as shipped with Red Hat Enterprise Linux 3, 4, or 5. It was corrected in Red Hat Enterprise Linux 6 via RHSA-2011:0545.
Package: squid (Red Hat Enterprise Linux 4) - Not affected
Package: squid (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=118467http://googlechromereleases.blogspot.com/2012/04/stable-and-beta-channel-updates.htmlhttp://osvdb.org/81042http://secunia.com/advisories/48732http://secunia.com/advisories/48749http://security.gentoo.org/glsa/glsa-201204-03.xmlhttp://www.securityfocus.com/bid/52913http://www.securitytracker.com/id?1026892https://exchange.xforce.ibmcloud.com/vulnerabilities/74632https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15480http://code.google.com/p/chromium/issues/detail?id=118467http://googlechromereleases.blogspot.com/2012/04/stable-and-beta-channel-updates.htmlhttp://osvdb.org/81042http://secunia.com/advisories/48732http://secunia.com/advisories/48749http://security.gentoo.org/glsa/glsa-201204-03.xmlhttp://www.securityfocus.com/bid/52913http://www.securitytracker.com/id?1026892https://exchange.xforce.ibmcloud.com/vulnerabilities/74632https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15480
2012-04-05
Published