VDB
CVE-2011-3640
CVE-2011-3640
PUBLISHED
CVSS 7.099999904632568 HIGH
** DISPUTED ** Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Chrome before 17 on Windows and Mac OS X, might allow local users to gain privileges via a Trojan horse pkcs11.txt file in a top-level directory. NOTE: the vendor's response was "Strange behavior, but we're not treating this as a security bug."
EPSS 1.39% · 71.3th percentile
Risk Scores
CVSS 2.0
7.099999904632568
EPSS Score
1.39%
71.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome | 0 | |
| n/a | n/a | * |
Timeline
- Oct 28, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=641052 url
- http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html exploit
- http://code.google.com/p/chromium/issues/detail?id=97426 exploit
- http://securityreason.com/securityalert/8483 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-3640 advisory
- https://hermes.opensuse.org/messages/13154861 url
- https://hermes.opensuse.org/messages/13155432 url
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13414 url