Lucene search

K
cve[email protected]CVE-2011-3055
HistoryMar 22, 2012 - 4:55 p.m.

CVE-2011-3055

2012-03-2216:55:01
CWE-306
web.nvd.nist.gov
28
cve-2011-3055
google chrome
remote attackers
user confirmation
unpacked extension installation
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.4%

The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.

Affected configurations

NVD
Node
googlechromeRange<17.0.963.83
Node
opensuseopensuseMatch12.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.4%