Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2011-3389

CVE-2011-3389, Severity pending severity (CVSS —): 3 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
-
Exploitation
73.3 %

EPSS, predicted over 30 days

Tracked apps
3
Still exposed
0

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

EPSS 73.33% exploit likely percentile 99.4%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Chrome macOS com.google.Chrome
    Affected - Fixed in - Latest tracked - undetermined
  • Google Chrome Windows winget:Google.Chrome
    Affected - Fixed in - Latest tracked 152.0.7977.65 undetermined
  • Mozilla Firefox Windows winget:Mozilla.Firefox
    Affected - Fixed in - Latest tracked 154.0.1 undetermined

NVD references 17 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (3)
Vendor Product Versions
google chrome
All platforms (wildcard)
-
google chrome
All platforms (wildcard)
-
mozilla firefox
All platforms (wildcard)
-
View on NVD ↗ Advisory · technet.microsoft.com Advisory · docs.microsoft.com Advisory · googlechromereleases.blogspot.com