CVE-2013-0922

UnknownEPSS 0.83%

Last modified

CVE-2013-0922 is a vulnerability of currently unknown severity. Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, which has unspecified impact and attack vectors.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.

Description

Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, which has unspecified impact and attack vectors.

Metrics

EPSS Probability
0.83%

52.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GoogleChrome<= 26.0.1410.42
GoogleChrome26.0.1410.0
GoogleChrome26.0.1410.1
GoogleChrome26.0.1410.2
GoogleChrome26.0.1410.3
GoogleChrome26.0.1410.4
GoogleChrome26.0.1410.5
GoogleChrome26.0.1410.6
GoogleChrome26.0.1410.7
GoogleChrome26.0.1410.8
GoogleChrome26.0.1410.9
GoogleChrome26.0.1410.10
GoogleChrome26.0.1410.11
GoogleChrome26.0.1410.12
GoogleChrome26.0.1410.14
GoogleChrome26.0.1410.15
GoogleChrome26.0.1410.16
GoogleChrome26.0.1410.17
GoogleChrome26.0.1410.18
GoogleChrome26.0.1410.19
GoogleChrome26.0.1410.20
GoogleChrome26.0.1410.21
GoogleChrome26.0.1410.22
GoogleChrome26.0.1410.23
GoogleChrome26.0.1410.24
GoogleChrome26.0.1410.25
GoogleChrome26.0.1410.26
GoogleChrome26.0.1410.27
GoogleChrome26.0.1410.28
GoogleChrome26.0.1410.29
GoogleChrome26.0.1410.30
GoogleChrome26.0.1410.31
GoogleChrome26.0.1410.32
GoogleChrome26.0.1410.33
GoogleChrome26.0.1410.34
GoogleChrome26.0.1410.35
GoogleChrome26.0.1410.36
GoogleChrome26.0.1410.37
GoogleChrome26.0.1410.38
GoogleChrome26.0.1410.39
GoogleChrome26.0.1410.40
GoogleChrome26.0.1410.41

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-0922?
Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, which has unspecified impact and attack vectors.
How severe is CVE-2013-0922?
Severity scoring for CVE-2013-0922 is pending analysis. The EPSS model estimates a 0.83% probability of exploitation in the next 30 days.
How do I fix CVE-2013-0922?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-0922?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST