Lucene search

K
cveChromeCVE-2012-5134
HistoryNov 28, 2012 - 1:55 a.m.

CVE-2012-5134

2012-11-2801:55:01
CWE-119
Chrome
web.nvd.nist.gov
58
cve-2012-5134
nvd
information security
buffer underflow
xmlparseattvaluecomplex
libxml2
denial of service
remote attackers
arbitrary code

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

9.7

Confidence

High

EPSS

0.044

Percentile

92.4%

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.

Affected configurations

Nvd
Node
googlechromeRange23.0.1271.89
OR
googlechromeMatch23.0.1271.0
OR
googlechromeMatch23.0.1271.1
OR
googlechromeMatch23.0.1271.2
OR
googlechromeMatch23.0.1271.3
OR
googlechromeMatch23.0.1271.4
OR
googlechromeMatch23.0.1271.5
OR
googlechromeMatch23.0.1271.6
OR
googlechromeMatch23.0.1271.7
OR
googlechromeMatch23.0.1271.8
OR
googlechromeMatch23.0.1271.10
OR
googlechromeMatch23.0.1271.11
OR
googlechromeMatch23.0.1271.12
OR
googlechromeMatch23.0.1271.13
OR
googlechromeMatch23.0.1271.14
OR
googlechromeMatch23.0.1271.15
OR
googlechromeMatch23.0.1271.16
OR
googlechromeMatch23.0.1271.17
OR
googlechromeMatch23.0.1271.18
OR
googlechromeMatch23.0.1271.19
OR
googlechromeMatch23.0.1271.20
OR
googlechromeMatch23.0.1271.21
OR
googlechromeMatch23.0.1271.22
OR
googlechromeMatch23.0.1271.23
OR
googlechromeMatch23.0.1271.24
OR
googlechromeMatch23.0.1271.26
OR
googlechromeMatch23.0.1271.30
OR
googlechromeMatch23.0.1271.31
OR
googlechromeMatch23.0.1271.32
OR
googlechromeMatch23.0.1271.33
OR
googlechromeMatch23.0.1271.35
OR
googlechromeMatch23.0.1271.36
OR
googlechromeMatch23.0.1271.37
OR
googlechromeMatch23.0.1271.38
OR
googlechromeMatch23.0.1271.39
OR
googlechromeMatch23.0.1271.40
OR
googlechromeMatch23.0.1271.41
OR
googlechromeMatch23.0.1271.44
OR
googlechromeMatch23.0.1271.45
OR
googlechromeMatch23.0.1271.46
OR
googlechromeMatch23.0.1271.49
OR
googlechromeMatch23.0.1271.50
OR
googlechromeMatch23.0.1271.51
OR
googlechromeMatch23.0.1271.52
OR
googlechromeMatch23.0.1271.53
OR
googlechromeMatch23.0.1271.54
OR
googlechromeMatch23.0.1271.55
OR
googlechromeMatch23.0.1271.56
OR
googlechromeMatch23.0.1271.57
OR
googlechromeMatch23.0.1271.58
OR
googlechromeMatch23.0.1271.60
OR
googlechromeMatch23.0.1271.61
OR
googlechromeMatch23.0.1271.62
OR
googlechromeMatch23.0.1271.64
OR
googlechromeMatch23.0.1271.83
OR
googlechromeMatch23.0.1271.84
OR
googlechromeMatch23.0.1271.85
OR
googlechromeMatch23.0.1271.86
OR
googlechromeMatch23.0.1271.87
OR
googlechromeMatch23.0.1271.88
OR
xmlsoftlibxml2Range2.9.0
OR
xmlsoftlibxml2Match1.7.0
OR
xmlsoftlibxml2Match1.7.1
OR
xmlsoftlibxml2Match1.7.2
OR
xmlsoftlibxml2Match1.7.3
OR
xmlsoftlibxml2Match1.7.4
OR
xmlsoftlibxml2Match1.8.0
OR
xmlsoftlibxml2Match1.8.1
OR
xmlsoftlibxml2Match1.8.2
OR
xmlsoftlibxml2Match1.8.3
OR
xmlsoftlibxml2Match1.8.4
OR
xmlsoftlibxml2Match1.8.5
OR
xmlsoftlibxml2Match1.8.6
OR
xmlsoftlibxml2Match1.8.7
OR
xmlsoftlibxml2Match1.8.9
OR
xmlsoftlibxml2Match1.8.10
OR
xmlsoftlibxml2Match1.8.13
OR
xmlsoftlibxml2Match1.8.14
OR
xmlsoftlibxml2Match1.8.16
OR
xmlsoftlibxml2Match2.0.0
OR
xmlsoftlibxml2Match2.1.0
OR
xmlsoftlibxml2Match2.1.1
OR
xmlsoftlibxml2Match2.2.0
OR
xmlsoftlibxml2Match2.2.0beta
OR
xmlsoftlibxml2Match2.2.1
OR
xmlsoftlibxml2Match2.2.2
OR
xmlsoftlibxml2Match2.2.3
OR
xmlsoftlibxml2Match2.2.4
OR
xmlsoftlibxml2Match2.2.5
OR
xmlsoftlibxml2Match2.2.6
OR
xmlsoftlibxml2Match2.2.7
OR
xmlsoftlibxml2Match2.2.8
OR
xmlsoftlibxml2Match2.2.9
OR
xmlsoftlibxml2Match2.2.10
OR
xmlsoftlibxml2Match2.2.11
OR
xmlsoftlibxml2Match2.3.0
OR
xmlsoftlibxml2Match2.3.1
OR
xmlsoftlibxml2Match2.3.2
OR
xmlsoftlibxml2Match2.3.3
OR
xmlsoftlibxml2Match2.3.4
OR
xmlsoftlibxml2Match2.3.5
OR
xmlsoftlibxml2Match2.3.6
OR
xmlsoftlibxml2Match2.3.7
OR
xmlsoftlibxml2Match2.3.8
OR
xmlsoftlibxml2Match2.3.9
OR
xmlsoftlibxml2Match2.3.10
OR
xmlsoftlibxml2Match2.3.11
OR
xmlsoftlibxml2Match2.3.12
OR
xmlsoftlibxml2Match2.3.13
OR
xmlsoftlibxml2Match2.3.14
OR
xmlsoftlibxml2Match2.4.1
OR
xmlsoftlibxml2Match2.4.2
OR
xmlsoftlibxml2Match2.4.3
OR
xmlsoftlibxml2Match2.4.4
OR
xmlsoftlibxml2Match2.4.5
OR
xmlsoftlibxml2Match2.4.6
OR
xmlsoftlibxml2Match2.4.7
OR
xmlsoftlibxml2Match2.4.8
OR
xmlsoftlibxml2Match2.4.9
OR
xmlsoftlibxml2Match2.4.10
OR
xmlsoftlibxml2Match2.4.11
OR
xmlsoftlibxml2Match2.4.12
OR
xmlsoftlibxml2Match2.4.13
OR
xmlsoftlibxml2Match2.4.14
OR
xmlsoftlibxml2Match2.4.15
OR
xmlsoftlibxml2Match2.4.16
OR
xmlsoftlibxml2Match2.4.17
OR
xmlsoftlibxml2Match2.4.18
OR
xmlsoftlibxml2Match2.4.19
OR
xmlsoftlibxml2Match2.4.20
OR
xmlsoftlibxml2Match2.4.21
OR
xmlsoftlibxml2Match2.4.22
OR
xmlsoftlibxml2Match2.4.23
OR
xmlsoftlibxml2Match2.4.24
OR
xmlsoftlibxml2Match2.4.25
OR
xmlsoftlibxml2Match2.4.26
OR
xmlsoftlibxml2Match2.4.27
OR
xmlsoftlibxml2Match2.4.28
OR
xmlsoftlibxml2Match2.4.29
OR
xmlsoftlibxml2Match2.4.30
OR
xmlsoftlibxml2Match2.5.0
OR
xmlsoftlibxml2Match2.5.4
OR
xmlsoftlibxml2Match2.5.7
OR
xmlsoftlibxml2Match2.5.8
OR
xmlsoftlibxml2Match2.5.10
OR
xmlsoftlibxml2Match2.5.11
OR
xmlsoftlibxml2Match2.6.0
OR
xmlsoftlibxml2Match2.6.1
OR
xmlsoftlibxml2Match2.6.2
OR
xmlsoftlibxml2Match2.6.3
OR
xmlsoftlibxml2Match2.6.4
OR
xmlsoftlibxml2Match2.6.5
OR
xmlsoftlibxml2Match2.6.6
OR
xmlsoftlibxml2Match2.6.7
OR
xmlsoftlibxml2Match2.6.8
OR
xmlsoftlibxml2Match2.6.9
OR
xmlsoftlibxml2Match2.6.11
OR
xmlsoftlibxml2Match2.6.12
OR
xmlsoftlibxml2Match2.6.13
OR
xmlsoftlibxml2Match2.6.14
OR
xmlsoftlibxml2Match2.6.16
OR
xmlsoftlibxml2Match2.6.17
OR
xmlsoftlibxml2Match2.6.18
OR
xmlsoftlibxml2Match2.6.20
OR
xmlsoftlibxml2Match2.6.22
OR
xmlsoftlibxml2Match2.6.26
OR
xmlsoftlibxml2Match2.6.27
OR
xmlsoftlibxml2Match2.6.30
OR
xmlsoftlibxml2Match2.6.32
OR
xmlsoftlibxml2Match2.7.0
OR
xmlsoftlibxml2Match2.7.1
OR
xmlsoftlibxml2Match2.7.2
OR
xmlsoftlibxml2Match2.7.3
OR
xmlsoftlibxml2Match2.7.4
OR
xmlsoftlibxml2Match2.7.5
OR
xmlsoftlibxml2Match2.7.6
OR
xmlsoftlibxml2Match2.7.7
OR
xmlsoftlibxml2Match2.9.0rc1
Node
appleiphone_osRange6.1.4
OR
appleiphone_osMatch1.0.0
OR
appleiphone_osMatch1.0.1
OR
appleiphone_osMatch1.0.2
OR
appleiphone_osMatch1.1.0
OR
appleiphone_osMatch1.1.1
OR
appleiphone_osMatch1.1.2
OR
appleiphone_osMatch1.1.3
OR
appleiphone_osMatch1.1.4
OR
appleiphone_osMatch1.1.5
OR
appleiphone_osMatch2.0
OR
appleiphone_osMatch2.0.0
OR
appleiphone_osMatch2.0.1
OR
appleiphone_osMatch2.0.2
OR
appleiphone_osMatch2.1
OR
appleiphone_osMatch2.1.1
OR
appleiphone_osMatch2.2
OR
appleiphone_osMatch2.2.1
OR
appleiphone_osMatch3.0
OR
appleiphone_osMatch3.0.1
OR
appleiphone_osMatch3.1
OR
appleiphone_osMatch3.1.2
OR
appleiphone_osMatch3.1.3
OR
appleiphone_osMatch3.2
OR
appleiphone_osMatch3.2.1
OR
appleiphone_osMatch3.2.2
OR
appleiphone_osMatch4.0
OR
appleiphone_osMatch4.0.1
OR
appleiphone_osMatch4.0.2
OR
appleiphone_osMatch4.1
OR
appleiphone_osMatch4.2.1
OR
appleiphone_osMatch4.2.5
OR
appleiphone_osMatch4.2.8
OR
appleiphone_osMatch4.3.0
OR
appleiphone_osMatch4.3.1
OR
appleiphone_osMatch4.3.2
OR
appleiphone_osMatch4.3.3
OR
appleiphone_osMatch4.3.5
OR
appleiphone_osMatch5.0
OR
appleiphone_osMatch5.0.1
OR
appleiphone_osMatch5.1
OR
appleiphone_osMatch5.1.1
OR
appleiphone_osMatch6.0
OR
appleiphone_osMatch6.0.1
OR
appleiphone_osMatch6.0.2
OR
appleiphone_osMatch6.1
OR
appleiphone_osMatch6.1.2
OR
appleiphone_osMatch6.1.3
VendorProductVersionCPE
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
googlechrome23.0.1271.0cpe:2.3:a:google:chrome:23.0.1271.0:*:*:*:*:*:*:*
googlechrome23.0.1271.1cpe:2.3:a:google:chrome:23.0.1271.1:*:*:*:*:*:*:*
googlechrome23.0.1271.2cpe:2.3:a:google:chrome:23.0.1271.2:*:*:*:*:*:*:*
googlechrome23.0.1271.3cpe:2.3:a:google:chrome:23.0.1271.3:*:*:*:*:*:*:*
googlechrome23.0.1271.4cpe:2.3:a:google:chrome:23.0.1271.4:*:*:*:*:*:*:*
googlechrome23.0.1271.5cpe:2.3:a:google:chrome:23.0.1271.5:*:*:*:*:*:*:*
googlechrome23.0.1271.6cpe:2.3:a:google:chrome:23.0.1271.6:*:*:*:*:*:*:*
googlechrome23.0.1271.7cpe:2.3:a:google:chrome:23.0.1271.7:*:*:*:*:*:*:*
googlechrome23.0.1271.8cpe:2.3:a:google:chrome:23.0.1271.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 2261

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

9.7

Confidence

High

EPSS

0.044

Percentile

92.4%