« Volver al listado

CVE-2011-2351

Estado: ModificadaMedia (6.8)—

Vulnerabilidad de uso después de liberación (use-after-free) en Google Chrome v12.0.742.112 permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores que implican el uso de elementos SVG.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-2351",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-06-29T17:55:04.473",
  "references": [
    {
      "url": "http://code.google.com/p/chromium/issues/detail?id=85211",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2011/06/stable-channel-update_28.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00004.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://secunia.com/advisories/45097",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://support.apple.com/kb/HT4981",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://support.apple.com/kb/HT4999",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://support.apple.com/kb/HT5000",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1025730",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14053",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://code.google.com/p/chromium/issues/detail?id=85211",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2011/06/stable-channel-update_28.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00004.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/45097",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT4981",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT4999",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT5000",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1025730",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14053",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de uso después de liberación (use-after-free) en Google Chrome v12.0.742.112 permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores que implican el uso de elementos SVG."
    }
  ],
  "lastModified": "2026-06-16T23:31:09.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0768F56-18C8-476C-B402-ED2522C46EC8",
              "versionEndExcluding": "12.0.742.112"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFDEF0C6-55A8-4240-AFFC-D3FC70F82F1D",
              "versionEndExcluding": "10.5"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5BF38A2-21DC-49F5-AA4B-2AD1596570B6",
              "versionEndExcluding": "5.1.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA5FD370-334D-48C5-946C-ADB9C5D7FCDF",
              "versionEndExcluding": "5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}