CVE-2012-5134
Last modified
CVE-2012-5134 is a vulnerability of currently unknown severity. Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.. EPSS estimates a 4.38% chance of exploitation in the next 30 days.
Description
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Chrome | <= 23.0.1271.89 | — | |
| Chrome | 23.0.1271.0 | — | |
| Chrome | 23.0.1271.1 | — | |
| Chrome | 23.0.1271.2 | — | |
| Chrome | 23.0.1271.3 | — | |
| Chrome | 23.0.1271.4 | — | |
| Chrome | 23.0.1271.5 | — | |
| Chrome | 23.0.1271.6 | — | |
| Chrome | 23.0.1271.7 | — | |
| Chrome | 23.0.1271.8 | — | |
| Chrome | 23.0.1271.10 | — | |
| Chrome | 23.0.1271.11 | — | |
| Chrome | 23.0.1271.12 | — | |
| Chrome | 23.0.1271.13 | — | |
| Chrome | 23.0.1271.14 | — | |
| Chrome | 23.0.1271.15 | — | |
| Chrome | 23.0.1271.16 | — | |
| Chrome | 23.0.1271.17 | — | |
| Chrome | 23.0.1271.18 | — | |
| Chrome | 23.0.1271.19 | — | |
| Chrome | 23.0.1271.20 | — | |
| Chrome | 23.0.1271.21 | — | |
| Chrome | 23.0.1271.22 | — | |
| Chrome | 23.0.1271.23 | — | |
| Chrome | 23.0.1271.24 | — | |
| Chrome | 23.0.1271.26 | — | |
| Chrome | 23.0.1271.30 | — | |
| Chrome | 23.0.1271.31 | — | |
| Chrome | 23.0.1271.32 | — | |
| Chrome | 23.0.1271.33 | — | |
| Chrome | 23.0.1271.35 | — | |
| Chrome | 23.0.1271.36 | — | |
| Chrome | 23.0.1271.37 | — | |
| Chrome | 23.0.1271.38 | — | |
| Chrome | 23.0.1271.39 | — | |
| Chrome | 23.0.1271.40 | — | |
| Chrome | 23.0.1271.41 | — | |
| Chrome | 23.0.1271.44 | — | |
| Chrome | 23.0.1271.45 | — | |
| Chrome | 23.0.1271.46 | — | |
| Chrome | 23.0.1271.49 | — | |
| Chrome | 23.0.1271.50 | — | |
| Chrome | 23.0.1271.51 | — | |
| Chrome | 23.0.1271.52 | — | |
| Chrome | 23.0.1271.53 | — | |
| Chrome | 23.0.1271.54 | — | |
| Chrome | 23.0.1271.55 | — | |
| Chrome | 23.0.1271.56 | — | |
| Chrome | 23.0.1271.57 | — | |
| Chrome | 23.0.1271.58 | — |
Showing 50 of 225 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5134?
How severe is CVE-2012-5134?
How do I fix CVE-2012-5134?
Are you affected by CVE-2012-5134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
