CVE-2013-2902 — Google Chrome vulnerability
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 17
Description
Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an applyXSLTransform call involving (1) an HTML document or (2) an xsl:processing-instruction element that is still in the process of loading.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages2 packages
Also affects: Debian Linux 7.0
🔴Vulnerability Details
1GHSA▶
GHSA-g2xj-3jcv-jw82: Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29↗2022-05-17
📋Vendor Advisories
1Debian▶
CVE-2013-2902: libxslt - Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in...↗2013