CVE-2011-3892

Google Chrome <15.0.874.120 - Use After Free

Title source: llm
STIX 2.1

Description

Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:076
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:075
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49089
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2471
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14484
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46933

Scores

EPSS 0.0186
EPSS Percentile 76.4%

Details

CWE
CWE-415
Status published
Products (2)
debian/debian_linux 6.0
google/chrome < 15.0.874.120
Published Nov 11, 2011
Tracked Since Feb 18, 2026