New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 6.7
SynopsisThe remote host contains a web browser that is affected by multiple vulnerabilities.
DescriptionThe version of Google Chrome installed on the remote host is earlier than 19.0.1084.46 and is, therefore, affected by the following vulnerabilities :
- Video content with FTP can cause crashes.
- Internal links are not loaded in their own process.
- Lengthy auto-filled values can corrupt the user interface. (CVE-2011-3085)
- Use-after free errors exist related to style elements, table handling, indexed DBs, GTK 'omnibox' handling, and corrupt font encoding names related to PDF handling.
(CVE-2011-3086, CVE-2011-3089, CVE-2011-3091, CVE-2011-3096, CVE-2011-3099)
- An error exists related to windows navigation.
- Out-of-bounds read errors exist related to hairline drawing, glyph handling, Tibetan, OGG containers, PDF sampled functions and drawing dash paths.
(CVE-2011-3088, CVE-2011-3093, CVE-2011-3094, CVE-2011-3095, CVE-2011-3097, CVE-2011-3100)
- A race condition related to workers exists.
- An invalid write exists in the v8 regex processing.
- An error exists related to Windows Media Player plugin and the search path. (CVE-2011-3098)
- An off-by-one out-of-bounds write error exists in libxml. (CVE-2011-3102)
SolutionUpgrade to Google Chrome 19.0.1084.46 or later.