CVE-2011-3880
published 2011-10-25CVE-2011-3880: Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote…
PriorityP427high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
0.88%
55.5th percentile
Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 15.0.874.102 | 15.0.874.102 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x83q-9458-9wwm: Google Chrome before 15
ghsa_unreviewed·2022-05-13
CVE-2011-3880 [HIGH] CWE-20 GHSA-x83q-9458-9wwm: Google Chrome before 15
Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.
Red Hat
kernel: inet_diag: insufficient validation
vendor_redhat·2011-06-01·CVSS 4.9
CVE-2011-2213 [MEDIUM] kernel: inet_diag: insufficient validation
kernel: inet_diag: insufficient validation
The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. Red Hat Enterprise Linux 4 is now in
Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included in the future u
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=95992http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/70958https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12672http://code.google.com/p/chromium/issues/detail?id=95992http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/70958https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12672
2011-10-25
Published