CVE-2013-2902Google Chrome vulnerability

CWE-3993 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateMay 17

Description

Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an applyXSLTransform call involving (1) an HTML document or (2) an xsl:processing-instruction element that is still in the process of loading.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDgoogle/chrome29.0.1547.56+50

Also affects: Debian Linux 7.0

🔴Vulnerability Details

1
GHSA
GHSA-g2xj-3jcv-jw82: Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 292022-05-17

📋Vendor Advisories

1
Debian
CVE-2013-2902: libxslt - Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in...2013