CVE-2013-2870

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 10 Jul 2013, 10:00
Last modified:06 Aug 2024, 15:52

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
1.72% LOW
2% probability +0.39%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Jul 2013, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:52
Last Modified
Vulnerability information updated

Description

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 1.72% Percentile: 83%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • debiandebian_linux

    7.0

  • googlechrome

    ≤ 28.0.1500.70 | 28.0.1500.0 | 28.0.1500.2 | 28.0.1500.3 | 28.0.1500.4 | 28.0.1500.5 | 28.0.1500.6 | 28.0.1500.8 | 28.0.1500.9 | 28.0.1500.10 | 28.0.1500.11 | 28.0.1500.12 | 28.0.1500.13 | 28.0.1500.14 | 28.0.1500.15 | 28.0.1500.16 | 28.0.1500.17 | 28.0.1500.18 | 28.0.1500.19 | 28.0.1500.20 | 28.0.1500.21 | 28.0.1500.22 | 28.0.1500.23 | 28.0.1500.24 | 28.0.1500.25 | 28.0.1500.26 | 28.0.1500.27 | 28.0.1500.28 | 28.0.1500.29 | 28.0.1500.31 | 28.0.1500.32 | 28.0.1500.33 | 28.0.1500.34 | 28.0.1500.35 | 28.0.1500.36 | 28.0.1500.37 | 28.0.1500.38 | 28.0.1500.39 | 28.0.1500.40 | 28.0.1500.41 | 28.0.1500.42 | 28.0.1500.43 | 28.0.1500.44 | 28.0.1500.45 | 28.0.1500.46 | 28.0.1500.47 | 28.0.1500.48 | 28.0.1500.49 | 28.0.1500.50 | 28.0.1500.51 | 28.0.1500.52 | 28.0.1500.53 | 28.0.1500.54 | 28.0.1500.56 | 28.0.1500.58 | 28.0.1500.59 | 28.0.1500.60 | 28.0.1500.61 | 28.0.1500.62 | 28.0.1500.63 | 28.0.1500.64 | 28.0.1500.66 | 28.0.1500.68

References (7)