Get real-time updates on Telegram
CVE-2011-3389: chrome Version not applicable in the source CPE; +15 more affected products
CVE-2011-3389. CVSS 2.0 base score 4.3 (MEDIUM, NVD). EPSS 0.73327 (percentile 0.99453), scored 2026-10-08.
Affected technology
chrome · Version not applicable in the source CPE
google
internet explorer · Version not applicable in the source CPE
microsoft
firefox · Version not applicable in the source CPE
mozilla
opera browser · Version not applicable in the source CPE
opera
windows · Version not applicable in the source CPE
microsoft
simatic rf68xr firmware · before 3.2.1 (exclusive)
siemens
simatic rf615r firmware · before 3.2.1 (exclusive)
siemens
curl · from 7.10.6 (inclusive), through 7.23.1 (inclusive)
haxx
enterprise linux desktop · 5.0
redhat
enterprise linux desktop · 6.0
redhat
enterprise linux eus · 6.2
redhat
enterprise linux server · 5.0
redhat
enterprise linux server · 6.0
redhat
enterprise linux server aus · 6.2
redhat
enterprise linux workstation · 5.0
redhat
enterprise linux workstation · 6.0
redhat
debian linux · 5.0
debian
debian linux · 6.0
debian
ubuntu linux · 10.04
canonical
ubuntu linux · 10.10
canonical
ubuntu linux · 11.04
canonical
ubuntu linux · 11.10
canonical
n/a · n/a
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (NVD, CVSS 2.0): Network (remote)
What an attacker can do
Man-in-the-middle attackers can obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack. NVD’s CVSS 2.0 assessment (base score 4.3/10) rates confidentiality impact as partial; integrity and availability impact as none.
- CWE
- CWE-326
- CCR priority
- 35.5 /100 (P4)
- CVSS 2.0
- 4.3 /10 · CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N · NVD
- EPSS
- 0.73327 · percentile 0.99453 · 2026-10-09
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-09 21:11:27.988868+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2011-3389.html