CVE-2013-2493
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Hook_Terminate function in chrome_frame/protocol_sink_wrap.cc in the Google Chrome Frame plugin before 26.0.1410.28 for Internet Explorer does not properly handle attach tab requests, which allows user-assisted remote attackers to cause a denial of service (application crash) via an _blank value for the target attribute of an A element.
la función Hook_Terminate de chrome_frame/protocol_sink_wrap.cc en complemento Google Chrome Frame antes de v26.0.1410.28 para Internet Explorer no manejan correctamente solicitar añadir pestañas, lo que permite a atacantes remotos asistidos por el usuario causar una denegación de servicio (caída de aplicación) a través de un valor _blank para el atributo de destino de un elemento A.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-03-07 CVE Reserved
- 2013-03-07 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2013/03/beta-channel-update.html | X_refsource_confirm | |
http://src.chromium.org/viewvc/chrome/trunk/src/chrome_frame/protocol_sink_wrap.cc?r1=185956&r2=185955&pathrev=185956 | X_refsource_confirm | |
https://code.google.com/p/chromium/issues/detail?id=178415 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://src.chromium.org/viewvc/chrome?view=rev&revision=185956 | 2013-03-08 | |
https://chromiumcodereview.appspot.com/12395021 | 2013-03-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Frame Search vendor "Google" for product "Chrome Frame" | <= 26.0.1410.27 Search vendor "Google" for product "Chrome Frame" and version " <= 26.0.1410.27" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Frame Search vendor "Google" for product "Chrome Frame" | 15.0.874.121 Search vendor "Google" for product "Chrome Frame" and version "15.0.874.121" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Frame Search vendor "Google" for product "Chrome Frame" | 16.0.912.63 Search vendor "Google" for product "Chrome Frame" and version "16.0.912.63" | - |
Affected
|