Code Injection in Google Chrome - CVE-2013-0912

 

Code Injection in Google Chrome - CVE-2013-0912

Published: March 11, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU43012
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0912
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."


Affected software

Google Chrome

How to mitigate CVE-2013-0912

Install update from vendor's website.


External References

Related Security Bulletins