CVE-2011-3908Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
2.3%
top 15.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 13

Description

Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDgoogle/chrome< 16.0.912.63
NVDapple/itunes< 10.6
NVDapple/safari< 5.1.4
NVDapple/iphone_os< 5.1

🔴Vulnerability Details

1
GHSA
GHSA-p399-7hr5-4w7m: Google Chrome before 162022-05-13