CVE-2011-3903 describes an out-of-bounds read vulnerability in Google Chrome versions prior to 16.0.912.63, stemming from improper regex matching. This flaw allows remote attackers to cause a denial of service. With a CVSS score of 5.0, it is considered medium severity, requiring no authentication and having low attack complexity, but only impacting availability. There is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and it is not listed in the KEV catalog, indicating low exploitation risk despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.912.63CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.