Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2011-3881

CVE-2011-3881, sévérité Sévérité en attente (CVSS —) : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
-
Exploitation
1.8 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0

EN WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ property, (3) the HTMLPlugInImageElement::allowedToLoadFrameURL function and use of a javascript: URL, (4) incorrect origins for XSLT-generated documents in the XSLTProcessor::createDocumentFromSource function, and (5) improper handling of synchronous frame loads in the ScriptController::executeIfJavaScriptURL function.

EPSS 1.76% au-dessus de la médiane percentile 76.4%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Safari macOS com.apple.Safari
    Affecté <5.1.4 Corrigé 5.1.4 Dernière suivie - indéterminé
  • Chrome macOS com.google.Chrome
    Affecté <15.0.874.102 Corrigé 15.0.874.102 Dernière suivie - indéterminé
  • Google Chrome Windows winget:Google.Chrome
    Affecté <15.0.874.102 Corrigé 15.0.874.102 Dernière suivie 152.0.7977.65 patchée
Configurations CPE vulnérables (3)
Vendor Produit Versions
google chrome
Toutes plateformes (wildcard)
<15.0.874.102
google chrome
Toutes plateformes (wildcard)
<15.0.874.102
apple safari
Toutes plateformes (wildcard)
<5.1.4
Voir sur NVD ↗