CVE-2012-5112
UnknownEPSS 4.64%
Last modified
CVE-2012-5112 is a vulnerability of currently unknown severity. Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.. EPSS estimates a 4.64% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | <= 22.0.1229.92 | |
| Chrome | 22.0.1229.0 | |
| Chrome | 22.0.1229.1 | |
| Chrome | 22.0.1229.2 | |
| Chrome | 22.0.1229.3 | |
| Chrome | 22.0.1229.4 | |
| Chrome | 22.0.1229.6 | |
| Chrome | 22.0.1229.7 | |
| Chrome | 22.0.1229.8 | |
| Chrome | 22.0.1229.9 | |
| Chrome | 22.0.1229.10 | |
| Chrome | 22.0.1229.11 | |
| Chrome | 22.0.1229.12 | |
| Chrome | 22.0.1229.14 | |
| Chrome | 22.0.1229.16 | |
| Chrome | 22.0.1229.17 | |
| Chrome | 22.0.1229.18 | |
| Chrome | 22.0.1229.20 | |
| Chrome | 22.0.1229.21 | |
| Chrome | 22.0.1229.22 | |
| Chrome | 22.0.1229.23 | |
| Chrome | 22.0.1229.24 | |
| Chrome | 22.0.1229.25 | |
| Chrome | 22.0.1229.26 | |
| Chrome | 22.0.1229.27 | |
| Chrome | 22.0.1229.28 | |
| Chrome | 22.0.1229.29 | |
| Chrome | 22.0.1229.31 | |
| Chrome | 22.0.1229.32 | |
| Chrome | 22.0.1229.33 | |
| Chrome | 22.0.1229.35 | |
| Chrome | 22.0.1229.36 | |
| Chrome | 22.0.1229.37 | |
| Chrome | 22.0.1229.39 | |
| Chrome | 22.0.1229.48 | |
| Chrome | 22.0.1229.49 | |
| Chrome | 22.0.1229.50 | |
| Chrome | 22.0.1229.51 | |
| Chrome | 22.0.1229.52 | |
| Chrome | 22.0.1229.53 | |
| Chrome | 22.0.1229.54 | |
| Chrome | 22.0.1229.55 | |
| Chrome | 22.0.1229.56 | |
| Chrome | 22.0.1229.57 | |
| Chrome | 22.0.1229.58 | |
| Chrome | 22.0.1229.59 | |
| Chrome | 22.0.1229.60 | |
| Chrome | 22.0.1229.62 | |
| Chrome | 22.0.1229.63 | |
| Chrome | 22.0.1229.64 |
Showing 50 of 58 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5112?
Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.
How severe is CVE-2012-5112?
Severity scoring for CVE-2012-5112 is pending analysis. The EPSS model estimates a 4.64% probability of exploitation in the next 30 days.
How do I fix CVE-2012-5112?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-5105Multiple cross-site scripting (XSS) vulnerabilities in SQLit…
- CVE-2012-5106Stack-based buffer overflow in FreeFloat FTP Server 1.0 allo…
- CVE-2012-5108Race condition in Google Chrome before 22.0.1229.92 allows r…
- CVE-2012-5109The International Components for Unicode (ICU) functionality…
- CVE-2012-5110The compositor in Google Chrome before 22.0.1229.92 allows r…
- CVE-2012-5111Google Chrome before 22.0.1229.92 does not monitor for crash…
- CVE-2012-5115Google Chrome before 23.0.1271.64 on Mac OS X does not prope…
- CVE-2012-5116Use-after-free vulnerability in Google Chrome before 23.0.12…
- CVE-2012-5117Google Chrome before 23.0.1271.64 does not properly restrict…
- CVE-2012-5118Google Chrome before 23.0.1271.64 on Mac OS X does not prope…
- CVE-2012-5119Race condition in Pepper, as used in Google Chrome before 23…
- CVE-2012-5120Google V8 before 3.13.7.5, as used in Google Chrome before 2…
Are you affected by CVE-2012-5112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
