cbcvebase.
CVE-2011-3640
published 2011-10-28

CVE-2011-3640: Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Chrome before 17 on Windows and Mac OS X, might allow local…

PriorityP426high7.1CVSS 2.0
AVNACHAuSCCICAC
EPSS
1.40%
69.4th percentile
Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Chrome before 17 on Windows and Mac OS X, might allow local users to gain privileges via a Trojan horse pkcs11.txt file in a top-level directory. NOTE: the vendor's response was "Strange behavior, but we're not treating this as a security bug."

Affected

6 ranges
VendorProductVersion rangeFixed in
debiannss< nss 3.13.1.with.ckbi.1.88-1 (bookworm)nss 3.13.1.with.ckbi.1.88-1 (bookworm)
googlechrome< 17.017.0
mozillanss>= 0 < 3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
mozillanss>= 0 < 3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
mozillanss>= 0 < 3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
mozillanss>= 0 < 3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1

CVSS provenance

nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.