CVE-2012-5112

Google Chrome < 22.0.1229.94 - Use-After-Free in SVG Implementation

Title source: llm
STIX 2.1

Description

Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.

References (13)

Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15523
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50954
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5567
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Nov/msg00000.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Nov/msg00001.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5568
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-11/0012.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/86149
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-11/0013.html

Scores

EPSS 0.0464
EPSS Percentile 90.8%

Details

CWE
CWE-399
Status published
Products (50)
apple/iphone_os 6.0
google/chrome 22.0.1229.0
google/chrome 22.0.1229.1
google/chrome 22.0.1229.2
google/chrome 22.0.1229.3
google/chrome 22.0.1229.4
google/chrome 22.0.1229.6
google/chrome 22.0.1229.7
google/chrome 22.0.1229.8
google/chrome 22.0.1229.9
... and 40 more
Published Oct 11, 2012
Tracked Since Feb 18, 2026