CVE-2012-4904
Last modified
CVE-2012-4904 is a vulnerability of currently unknown severity. Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | <= 18.0.1025306 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4904?
How severe is CVE-2012-4904?
How do I fix CVE-2012-4904?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-4898Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does …
- CVE-2012-4899WellinTech KingView 6.5.3 and earlier uses a weak password-h…
- CVE-2012-4900Corel WordPerfect Office X6 16.0.0.388 has a DoS Vulnerabili…5.5
- CVE-2012-4901Cross-site scripting (XSS) vulnerability in Template CMS 2.1…
- CVE-2012-4902Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-4903Google Chrome before 18.0.1025308 on Android does not proper…
- CVE-2012-4905Cross-site scripting (XSS) vulnerability in Google Chrome be…
- CVE-2012-4906Google Chrome before 18.0.1025308 on Android does not proper…
- CVE-2012-4907Google Chrome before 18.0.1025308 on Android does not proper…
- CVE-2012-4908Google Chrome before 18.0.1025308 on Android allows remote a…
- CVE-2012-4909Google Chrome before 18.0.1025308 on Android allows remote a…
- CVE-2012-4910Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2012-4904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
