Sploitus

CVE-2011-4692

1 known exploit for CVE-2011-4692

WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.

Affected products
Google Chrome, Safari, Webkit
Apple Safari
≤ 5.1.1
Apple Webkit
All versions
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
1.2% (65th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2011-12-07
CVE-2011-4692 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-4692

Proof-of-concept code and exploit modules indexed by Sploitus