CVE-2013-0888Out-of-bounds Read in Google Chrome

Severity
5.0MEDIUMNVD
EPSS
0.7%
top 27.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateMay 14

Description

Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a "user gesture check for dangerous file downloads."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDgoogle/chrome< 25.0.1364.97+1
NVDopensuse/opensuse12.1, 12.2+1

🔴Vulnerability Details

1
GHSA
GHSA-j4xp-34j6-4m86: Skia, as used in Google Chrome before 252022-05-14

💬Community

1
Bugzilla
CVE-2013-2144 rhevm: insufficient target domain permission check when cloning a VM from a snapshot2013-06-05
CVE-2013-0888 — Out-of-bounds Read in Google Chrome | cvebase