CVE-2011-3059 describes an out-of-bounds read vulnerability in Google Chrome versions prior to 18.0.1025.142, affecting various Apple and Google products utilizing the Chrome browser engine. This flaw, stemming from improper handling of SVG text elements, allows remote attackers to trigger a denial of service. With a CVSS score of 6.8, it is considered a medium-severity vulnerability, requiring medium attack complexity and potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Despite limited community discussion and media coverage, its FAUCET Risk Score of 45/100 indicates a moderate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.1025.142CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.