Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-5319

Опубликовано: 09 мар. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

РелизСтатусПримечание
devel

released

41.0.2272.76-0ubuntu1.1134
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [41.0.2272.76-0ubuntu0.14.04.1.1076]]
lucid

ignored

end of life
precise

ignored

trusty

released

41.0.2272.76-0ubuntu0.14.04.1.1076
trusty/esm

DNE

trusty was released [41.0.2272.76-0ubuntu0.14.04.1.1076]
upstream

released

41.0.2272.76
utopic

released

41.0.2272.76-0ubuntu0.14.10.1.1118
vivid

released

41.0.2272.76-0ubuntu1.1134
wily

released

41.0.2272.76-0ubuntu1.1134

Показывать по

EPSS

Процентиль: 58%
0.00373
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

debian
почти 11 лет назад

content/renderer/device_sensors/device_motion_event_pump.cc in Google ...

github
больше 3 лет назад

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

EPSS

Процентиль: 58%
0.00373
Низкий

5 Medium

CVSS2