Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0480

28
FAUCET Score

CVE-2011-0480 describes multiple buffer overflows in the FFmpeg Vorbis decoder, specifically affecting Google Chrome and Chrome OS. This critical vulnerability (CVSS 9.3) allows remote attackers to trigger a denial of service (memory corruption, application crash) or potentially other unspecified impacts by providing a crafted WebM file. While the attack complexity is medium, the potential impact on confidentiality, integrity, and availability is complete. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.0.552.344CPE matchmatch criteria
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*
< 8.0.552.237CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
8.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
9.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.30%
Probability of exploitation in next 30 days
EPSS Percentile
81.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0230 is in the 38th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

asteriskpatch availablevia llm_extracted
Fixed in: 0.5.4
View patch
bitbucketpatch availablevia llm_extracted
Fixed in: 0.5.4
elementpatch availablevia llm_extracted
Fixed in: 0.5.4
gl_inetpatch availablevia llm_extracted
Fixed in: 0.5.4
jfrogpatch availablevia llm_extracted
Fixed in: 0.5.4

Vendor Advisories (5)

jfrogllm-jfrog-129683e78473e159

Multiple vulnerabilities fixed in FFmpeg 0.5.4

asteriskllm-asterisk-638e91a96e517b9e

Multiple vulnerabilities fixed in FFmpeg 0.5.4

gl_inetllm-gl_inet-3efe299aabbf188e

Multiple vulnerabilities fixed in FFmpeg 0.5.4

bitbucketllm-bitbucket-01dd5238563110e5

Multiple vulnerabilities fixed in FFmpeg 0.5.4

elementllm-element-e999936709af1d5d

Multiple vulnerabilities fixed in FFmpeg 0.5.4

References

article.gmane.org / gmane.comp.video.ffmpeg.devel/122703
Broken Link
bugs.debian.org / cgi-bin/bugreport.cgi
Issue TrackingThird Party Advisory
code.google.com / p/chromium/issues/detail
ExploitIssue TrackingPatchVendor Advisory
codereview.chromium.org / 5964011
PatchVendor Advisory
codereview.chromium.org / 6069005
Vendor Advisory
ffmpeg.mplayerhq.hu
Third Party Advisory
git.ffmpeg.org
googlechromereleases.blogspot.com / 2011/01/chrome-stable-release.html
Vendor Advisory
osvdb.org / 70463
Broken Link
roundup.ffmpeg.org / issue2548
Broken Link
roundup.ffmpeg.org / issue2550
Broken Link
secunia.com / advisories/42951
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/64671
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14380
Third Party Advisory
src.chromium.org / viewvc/chrome
Broken Link
debian.org / security/2011/dsa-2306
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
securityfocus.com / bid/45788
Third Party AdvisoryVDB Entry
srware.net / forum/viewtopic.php
Third Party Advisory
ubuntu.com / usn/usn-1104-1
Third Party Advisory