10

CVE-2011-1300

The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 4.0
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta1
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta10
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta11
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta12
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta2
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta3
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta4
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta5
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta6
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta7
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta8
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version 4.0 Update beta9
   Microsoft ≫ Windows Version -
Google ≫ Chrome Version < 10.0.648.205
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.01% 0.858
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html
Vendor Advisory
http://secunia.com/advisories/44141
Vendor Advisory
http://code.google.com/p/angleproject/source/detail?r=611
Vendor Advisory
http://code.google.com/p/chromium/issues/detail?id=70070
Vendor Advisory
http://www.mozilla.org/security/announce/2011/mfsa2011-17.html
Vendor Advisory
http://www.securityfocus.com/bid/47377
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1025377
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2011/1006
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=623791
Vendor Advisory
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/66766
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14466
Third Party Advisory