Back to search
CVE-2011-3046
Published: Mar 9, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
52369
vdb-entry
x_refsource_BID
https://plus.google.com/u/0/116651741222993143554/posts/5Eq5d9XgFqs
x_refsource_CONFIRM
48527
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2012-05-07-1
vendor-advisory
x_refsource_APPLE
http://code.google.com/p/chromium/issues/detail?id=117226
x_refsource_CONFIRM
http://support.apple.com/kb/HT5282
x_refsource_CONFIRM
48419
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2012-05-09-2
vendor-advisory
x_refsource_APPLE
openSUSE-SU-2012:0374
vendor-advisory
x_refsource_SUSE
48321
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:14686
vdb-entry
signature
x_refsource_OVAL
http://code.google.com/p/chromium/issues/detail?id=117230
x_refsource_CONFIRM
GLSA-201203-19
vendor-advisory
x_refsource_GENTOO
47292
third-party-advisory
x_refsource_SECUNIA
1026776
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now