VDB
CVE-2011-2599
CVE-2011-2599
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
EPSS 0.81% · 55.2th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.81%
55.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| chrome | 11 |
Timeline
- Jun 30, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
References
- http://www.contextis.co.uk/resources/blog/webgl/ exploit
- https://nvd.nist.gov/vuln/detail/CVE-2011-2599 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14183 url
- http://lists.whatwg.org/pipermail/whatwg-whatwg.org/2011-March/030882.html url
- http://www.contextis.co.uk/resources/blog/webgl url