CVE-2011-3055

The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
googlechrome
𝑥
< 17.0.963.83
opensuseopensuse
12.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
oneiric
Fixed 18.0.1025.142~r129054-0ubuntu0.11.10.1
released
natty
Fixed 18.0.1025.142~r129054-0ubuntu0.11.04.1
released
maverick
Fixed 18.0.1025.151~r130497-0ubuntu0.10.10.1
released
lucid
Fixed 18.0.1025.151~r130497-0ubuntu0.10.04.1
released
hardy
dne