CVE-2011-3105
published 2012-05-24CVE-2011-3105: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.80%
76.4th percentile
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
Affected
132 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 19.0.1084.51 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:13.0/ rv:10.0.5) (MFSA 2012-34)
vendor_redhat·2012-06-05·CVSS 10.0
CVE-2012-3105 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:13.0/ rv:10.0.5) (MFSA 2012-34)
Mozilla: Miscellaneous memory safety hazards (rv:13.0/ rv:10.0.5) (MFSA 2012-34)
The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a related issue to CVE-2011-3101.
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:13.0/ rv:10.0.5) (MFSA 2012-34)
vendor_redhat·2012-06-05·CVSS 10.0
CVE-2011-3101 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:13.0/ rv:10.0.5) (MFSA 2012-34)
Mozilla: Miscellaneous memory safety hazards (rv:13.0/ rv:10.0.5) (MFSA 2012-34)
Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVIDIA driver, which has unknown impact and attack vectors. NOTE: see CVE-2012-3105 for the related MFSA 2012-34 issue in Mozilla products.
Red Hat
webkitgtk: Use-after-free in first-letter handling
vendor_redhat·2012-05-23·CVSS 7.5
CVE-2011-3105 [HIGH] CWE-416 webkitgtk: Use-after-free in first-letter handling
webkitgtk: Use-after-free in first-letter handling
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
Statement: This issue affects the version of webkitgtk as shipped with Red Hat Enterprise Linux 6.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Affected
GHSA
GHSA-fqq3-69m6-g84r: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19
ghsa_unreviewed·2022-05-17
CVE-2011-3105 [HIGH] GHSA-fqq3-69m6-g84r: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3105 webkitgtk: Use-after-free in first-letter handling
bugzilla·2012-05-29·CVSS 7.5
CVE-2011-3105 [HIGH] CVE-2011-3105 webkitgtk: Use-after-free in first-letter handling
CVE-2011-3105 webkitgtk: Use-after-free in first-letter handling
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-3105 to the following vulnerability:
Name: CVE-2011-3105
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3105
Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=120912
Reference: CONFIRM:http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.html
Use-after-free vulnerability in the Cascading Style Sheets (CSS)
implementation in Google Chrome before 19.0.1084.52 allows remote
attackers to cause a denial of service or possibly have unspecified
other impact via vectors related to the :first-letter pseudo-element.
Discussion:
References:
webkit bug: https://bugs.webkit.org/show_bug.cgi?id=86133
Patch: http:
Bugzilla
Webkitgtk: google chrome update [23-May-2012]
bugzilla·2012-05-29·CVSS 7.5
[HIGH] Webkitgtk: google chrome update [23-May-2012]
Webkitgtk: google chrome update [23-May-2012]
This bug is to collect statements for Webkit-related CVE's that do not have their own top-level CVE SRT bug because it did not affect the version of webkitgtk or konquerer shipped with Red Hat Enterprise Linux. These statements were also referred to as NVD statements and are noted on the NVD web site.
This bug is used for webkit security issues disclosed in the following google chrome security advisory:
http://googlechromereleases.blogspot.in/2012/05/stable-channel-update_23.html
Discussion:
CVE-2011-3105 affects the version of webkitgtk shipped with Red Hat Enterprise Linux 6, a separate bug has been filed for it.
Other flaws reported on the google chrome security advisory do not affect Webkit
http://code.google.com/p/chromium/issues/detail?id=120912http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00005.htmlhttp://osvdb.org/82242http://secunia.com/advisories/49277http://secunia.com/advisories/49306http://security.gentoo.org/glsa/glsa-201205-04.xmlhttp://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5502http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/53679http://www.securitytracker.com/id?1027098https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15535http://code.google.com/p/chromium/issues/detail?id=120912http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00005.htmlhttp://osvdb.org/82242http://secunia.com/advisories/49277http://secunia.com/advisories/49306http://security.gentoo.org/glsa/glsa-201205-04.xmlhttp://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5502http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/53679http://www.securitytracker.com/id?1027098https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15535
2012-05-24
Published