CVE-2011-3046
09.03.2012, 00:55
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
| Vendor | Product | Version |
|---|---|---|
| chrome | 𝑥 < 17.0.963.78 | |
| opensuse | opensuse | 12.1 |
| apple | safari | 𝑥 < 5.1.7 |
| apple | iphone_os | 𝑥 < 5.1.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium-browser |
| ||||||||||||||||
| webkit |
|
References