Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2904

Опубликовано: 21 авг. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.

РелизСтатусПримечание
devel

not-affected

29.0.1547.65-0ubuntu2
lucid

ignored

end of life
precise

released

30.0.1599.114-0ubuntu0.12.04.3
quantal

released

30.0.1599.114-0ubuntu0.12.10.2
raring

released

30.0.1599.114-0ubuntu0.13.04.2
saucy

not-affected

29.0.1547.65-0ubuntu2
upstream

released

29.0.1547.57

Показывать по

EPSS

Процентиль: 74%
0.01627
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.

debian
около 13 лет назад

Use-after-free vulnerability in the Document::finishedParsing function ...

github
больше 4 лет назад

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.

EPSS

Процентиль: 74%
0.01627
Низкий

7.5 High

CVSS2