CVE-2013-7324

MEDIUM

webkitgtk 2.0.0-2.26.4 - Unauthenticated High Volume Audio Output via JavaScript

Title source: llm
STIX 2.1

Description

Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2014/02/10/13
Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2013/10/08/4

Scores

CVSS v3 5.3
EPSS 0.0143
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-74
Status published
Products (1)
webkitgtk/webkitgtk 2.0.0 - 2.26.4
Published Feb 17, 2020
Tracked Since Feb 18, 2026