Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5283

Опубликовано: 27 мая 2025
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rhel10/firefox-flatpakAffected
Red Hat Enterprise Linux 10rhel10/thunderbird-flatpakAffected
Red Hat Enterprise Linux 6libvpxOut of support scope
Red Hat Enterprise Linux 7libvpxAffected
Red Hat Enterprise Linux 10firefoxFixedRHSA-2025:834102.06.2025
Red Hat Enterprise Linux 10thunderbirdFixedRHSA-2025:860805.06.2025
Red Hat Enterprise Linux 10libvpxFixedRHSA-2025:912016.06.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupportfirefoxFixedRHSA-2025:907416.06.2025
Red Hat Enterprise Linux 8firefoxFixedRHSA-2025:830829.05.2025
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2025:875610.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2368749libvpx: Double-free in libvpx encoder

EPSS

Процентиль: 25%
0.00081
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.4
nvd
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

msrc
20 дней назад

Chromium: CVE-2025-5283 Use after free in libvpx

CVSS3: 5.4
debian
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allow ...

CVSS3: 5.4
github
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

EPSS

Процентиль: 25%
0.00081
Низкий

8.1 High

CVSS3

Уязвимость CVE-2025-5283