CVE-2011-3895 describes a heap-based buffer overflow in the Vorbis decoder of Google Chrome, affecting versions prior to 15.0.874.120, as well as Debian Chrome and Debian Linux. This vulnerability carries a CVSS score of 7.5, indicating high severity due to its network-based attack vector and low attack complexity, potentially leading to denial of service, information disclosure, or arbitrary code execution. While there is no evidence of active exploitation (not in KEV or Hot List) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.874.120CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities fixed in FFmpeg 0.8.10
Multiple vulnerabilities fixed in FFmpeg 0.6.5
Multiple vulnerabilities fixed in FFmpeg 0.8.10
Multiple vulnerabilities fixed in FFmpeg 0.7.11
Multiple vulnerabilities fixed in FFmpeg 0.6.5
Multiple vulnerabilities fixed in FFmpeg 0.5.8
Multiple vulnerabilities fixed in FFmpeg 0.8.10
Multiple vulnerabilities fixed in FFmpeg 0.7.11
Multiple vulnerabilities fixed in FFmpeg 0.6.5
Multiple vulnerabilities fixed in FFmpeg 0.5.8
Multiple vulnerabilities fixed in FFmpeg 0.8.10
Multiple vulnerabilities fixed in FFmpeg 0.7.11
Multiple vulnerabilities fixed in FFmpeg 0.6.5
Multiple vulnerabilities fixed in FFmpeg 0.5.8
Multiple vulnerabilities fixed in FFmpeg 0.8.10
Multiple vulnerabilities fixed in FFmpeg 0.7.11
Multiple vulnerabilities fixed in FFmpeg 0.6.5
Multiple vulnerabilities fixed in FFmpeg 0.5.8