CVE-2012-2890
Last modified
CVE-2012-2890 is a vulnerability of currently unknown severity. Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | <= 22.0.1229.78 | |
| Chrome | 22.0.1229.0 | |
| Chrome | 22.0.1229.1 | |
| Chrome | 22.0.1229.2 | |
| Chrome | 22.0.1229.3 | |
| Chrome | 22.0.1229.4 | |
| Chrome | 22.0.1229.6 | |
| Chrome | 22.0.1229.7 | |
| Chrome | 22.0.1229.8 | |
| Chrome | 22.0.1229.9 | |
| Chrome | 22.0.1229.10 | |
| Chrome | 22.0.1229.11 | |
| Chrome | 22.0.1229.12 | |
| Chrome | 22.0.1229.14 | |
| Chrome | 22.0.1229.16 | |
| Chrome | 22.0.1229.17 | |
| Chrome | 22.0.1229.18 | |
| Chrome | 22.0.1229.20 | |
| Chrome | 22.0.1229.21 | |
| Chrome | 22.0.1229.22 | |
| Chrome | 22.0.1229.23 | |
| Chrome | 22.0.1229.24 | |
| Chrome | 22.0.1229.25 | |
| Chrome | 22.0.1229.26 | |
| Chrome | 22.0.1229.27 | |
| Chrome | 22.0.1229.28 | |
| Chrome | 22.0.1229.29 | |
| Chrome | 22.0.1229.31 | |
| Chrome | 22.0.1229.32 | |
| Chrome | 22.0.1229.33 | |
| Chrome | 22.0.1229.35 | |
| Chrome | 22.0.1229.36 | |
| Chrome | 22.0.1229.37 | |
| Chrome | 22.0.1229.39 | |
| Chrome | 22.0.1229.48 | |
| Chrome | 22.0.1229.49 | |
| Chrome | 22.0.1229.50 | |
| Chrome | 22.0.1229.51 | |
| Chrome | 22.0.1229.52 | |
| Chrome | 22.0.1229.53 | |
| Chrome | 22.0.1229.54 | |
| Chrome | 22.0.1229.55 | |
| Chrome | 22.0.1229.56 | |
| Chrome | 22.0.1229.57 | |
| Chrome | 22.0.1229.58 | |
| Chrome | 22.0.1229.59 | |
| Chrome | 22.0.1229.60 | |
| Chrome | 22.0.1229.62 | |
| Chrome | 22.0.1229.63 | |
| Chrome | 22.0.1229.64 |
Showing 50 of 53 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2890?
How severe is CVE-2012-2890?
How do I fix CVE-2012-2890?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-2884Skia, as used in Google Chrome before 22.0.1229.79, allows r…
- CVE-2012-2885Double free vulnerability in Google Chrome before 22.0.1229.…
- CVE-2012-2886Cross-site scripting (XSS) vulnerability in Google Chrome be…
- CVE-2012-2887Use-after-free vulnerability in Google Chrome before 22.0.12…
- CVE-2012-2888Use-after-free vulnerability in Google Chrome before 22.0.12…
- CVE-2012-2889Cross-site scripting (XSS) vulnerability in Google Chrome be…
- CVE-2012-2891The IPC implementation in Google Chrome before 22.0.1229.79 …
- CVE-2012-2892Unspecified vulnerability in Google Chrome before 22.0.1229.…
- CVE-2012-2893Double free vulnerability in libxslt, as used in Google Chro…
- CVE-2012-2894Google Chrome before 22.0.1229.79 does not properly handle g…
- CVE-2012-2895The PDF functionality in Google Chrome before 22.0.1229.79 a…
- CVE-2012-2896Integer overflow in the WebGL implementation in Google Chrom…
Are you affected by CVE-2012-2890?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
