Lucene search

K
cve[email protected]CVE-2011-0480
HistoryJan 14, 2011 - 5:00 p.m.

CVE-2011-0480

2011-01-1417:00:03
CWE-120
web.nvd.nist.gov
53
cve
2011
0480
buffer overflow
vorbis decoder
ffmpeg
google chrome
denial of service
memory corruption
application crash
webm file
chrome os

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.9%

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.

Affected configurations

NVD
Node
googlechrome_osRange<8.0.552.344
Node
googlechromeRange<8.0.552.237
Node
debiandebian_linuxMatch6.0
Node
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.9%