CVE-2011-3019 describes a heap-based buffer overflow vulnerability in Google Chrome versions prior to 17.0.963.56. This flaw can be triggered remotely by a crafted Matroska (MKV) video file, potentially leading to a denial of service or other unspecified impacts. With a CVSS score of 6.8, it is considered a medium-severity vulnerability, requiring user interaction (medium attack complexity) but allowing remote exploitation. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0.963.56CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.