CVE-2011-1187

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."

References

http://code.google.com/p/chromium/issues/detail?id=69187

http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.html

http://secunia.com/advisories/48972

http://secunia.com/advisories/49047

http://secunia.com/advisories/49055

http://www.mozilla.org/security/announce/2012/mfsa2012-32.html

http://www.securityfocus.com/bid/46785

http://www.vupen.com/english/advisories/2011/0628

https://bugzilla.mozilla.org/show_bug.cgi?id=624621

https://exchange.xforce.ibmcloud.com/vulnerabilities/65951

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14369

Details

Source: MITRE

Published: 2011-03-11

Updated: 2020-06-03

Type: CWE-200

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
74612openSUSE Security Update : MozillaFirefox / MozillaThunderbird / seamonkey / etc (openSUSE-SU-2012:0567-1)NessusSuSE Local Security Checks
critical
801359Mozilla Firefox <= 11 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801320Mozilla SeaMonkey 2.x < 2.9.0 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801261Mozilla Thunderbird < 12 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
6792Mozilla Thunderbird < 12.0 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6791SeaMonkey 2.x < 2.9.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6790Mozilla Firefox < 12.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
59354SuSE 10 Security Update : MozillaFirefox (ZYPP Patch Number 8154)NessusSuSE Local Security Checks
critical
59015Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : thunderbird vulnerabilities (USN-1430-3)NessusUbuntu Local Security Checks
critical
58973SuSE 11.1 Security Update : Mozilla Firefox (SAT Patch Number 6224)NessusSuSE Local Security Checks
critical
58923Ubuntu 10.04 LTS / 11.04 / 11.10 : ubufox update (USN-1430-2)NessusUbuntu Local Security Checks
critical
58922Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : firefox vulnerabilities (USN-1430-1)NessusUbuntu Local Security Checks
critical
58901SeaMonkey < 2.9.0 Multiple VulnerabilitiesNessusWindows
high
58900Mozilla Thunderbird < 12.0 Multiple VulnerabilitiesNessusWindows
high
58898Firefox < 12.0 Multiple VulnerabilitiesNessusWindows
high
58896Thunderbird < 12.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
58894Firefox < 12.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
58864FreeBSD : mozilla -- multiple vulnerabilities (380e8c56-8e32-11e1-9580-4061862b8c22)NessusFreeBSD Local Security Checks
critical
800960Google Chrome < 10.0.648.127 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
5812Google Chrome < 10.0.648.127 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
52589Google Chrome < 10.0.648.127 Multiple VulnerabilitiesNessusWindows
medium