« Volver al listado

CVE-2011-1042

Estado: ModificadaMedia (4.3)—

Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta allows user-assisted remote attackers to cause a denial of service (daemon crash) by providing the name of a hidden WiFi network that does not respond to connection attempts.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-1042",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-02-18T17:00:46.323",
  "references": [
    {
      "url": "http://code.google.com/p/chromium-os/issues/detail?id=8871",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://codereview.chromium.org/5255012",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2011/01/chrome-os-beta-channel-update.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65556",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://code.google.com/p/chromium-os/issues/detail?id=8871",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://codereview.chromium.org/5255012",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2011/01/chrome-os-beta-channel-update.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65556",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta allows user-assisted remote attackers to cause a denial of service (daemon crash) by providing the name of a hidden WiFi network that does not respond to connection attempts."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad uso después de liberación en flimflamd en flimflam en Google Chrome OS antes de v0.9.130.14 beta permite provocar una denegación de servicio (por bloqueo del demonio) a atacantes remotos asistidos por un usuario local, proporcionando el nombre de una red WiFi oculta que no responde a los intentos de conexión."
    }
  ],
  "lastModified": "2026-06-16T23:28:36.207",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F2B81FD-97CB-4640-98FB-82917D3BF396",
              "versionEndIncluding": "0.9.126.0"
            },
            {
              "criteria": "cpe:2.3:o:google:chrome_os:8.0.552.342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB46097B-CAC0-4AD0-8B2C-D661128040EF"
            },
            {
              "criteria": "cpe:2.3:o:google:chrome_os:8.0.552.343:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BD09AD8-3300-411F-9268-DDA758F71B0D"
            },
            {
              "criteria": "cpe:2.3:o:google:chrome_os:8.0.552.344:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06A030EE-2368-46B8-9D80-EC5356216026"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}