CVE-2022-1311
published 2022-07-25CVE-2022-1311: Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.85%
54.5th percentile
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 100.0.4896.88-1~deb11u1 | 100.0.4896.88-1~deb11u1 |
| chromium | chromium | >= 0 < 100.0.4896.88-1 | 100.0.4896.88-1 |
| chromium | chromium | >= 0 < 100.0.4896.88-1 | 100.0.4896.88-1 |
| chromium | chromium | >= 0 < 100.0.4896.88-1 | 100.0.4896.88-1 |
| debian | chromium | < chromium 100.0.4896.88-1 (bookworm) | chromium 100.0.4896.88-1 (bookworm) |
| chrome | < 100.0.4896.88 | 100.0.4896.88 | |
| chrome | >= unspecified < 100.0.4896.88 | 100.0.4896.88 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_oracle8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Common (Apache Xerces-C) — CVE-2018-1311
vendor_oracle·2022-10-15·CVSS 8.1
CVE-2018-1311 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Common (Apache Xerces-C) — CVE-2018-1311
Oracle Oracle Communications Applications Risk Matrix: Common (Apache Xerces-C) vulnerability
CVE: CVE-2018-1311
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Chrome
Long Term Support Channel Update: CVE-2022-1311
vendor_chrome·2022-04-28·CVSS 8.8
CVE-2022-1311 [HIGH] Long Term Support Channel Update: CVE-2022-1311
Long Term Support Channel Update
CVE-2022-1311: Use after free in Chrome OS shell. 1292261 High CVE-2022-1125: Use after free in Portals
Severity: high
Oracle
Oracle Oracle GoldenGate Risk Matrix: Build Request (Apache Xerces-C++) — CVE-2018-1311
vendor_oracle·2022-01-15·CVSS 8.1
CVE-2018-1311 [HIGH] Oracle Oracle GoldenGate Risk Matrix: Build Request (Apache Xerces-C++) — CVE-2018-1311
Oracle Oracle GoldenGate Risk Matrix: Build Request (Apache Xerces-C++) vulnerability
CVE: CVE-2018-1311
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Debian
CVE-2022-1311: chromium - Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allo...
vendor_debian·2022·CVSS 8.8
CVE-2022-1311 [HIGH] CVE-2022-1311: chromium - Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allo...
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fixed in 100.0.4896.88-1)
trixie: resolved (fixed in 100.0.4896.88-1)
GHSA
GHSA-xw76-qw2j-v4fp: Use after free in shell in Google Chrome on ChromeOS prior to 100
ghsa_unreviewed·2022-07-26
CVE-2022-1311 [HIGH] CWE-416 GHSA-xw76-qw2j-v4fp: Use after free in shell in Google Chrome on ChromeOS prior to 100
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-1311: Use after free in shell in Google Chrome on ChromeOS prior to 100
osv·2022-07-25·CVSS 8.8
CVE-2022-1311 [HIGH] CVE-2022-1311: Use after free in shell in Google Chrome on ChromeOS prior to 100
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_11.htmlhttps://crbug.com/1310717https://security.gentoo.org/glsa/202208-25https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_11.htmlhttps://crbug.com/1310717https://security.gentoo.org/glsa/202208-25
2022-07-25
Published