Back to Database
Status published
Medium
CVE-2012-2890
Use-after-free vulnerability in the PDF functionality in Google Chrome before...
Vulnerability Description
Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2890
Credits & Attribution
No credits recorded in the NVD database.
References
- https://code.google.com/p/chromium/issues/detail?id=144072
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15766
- http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html
- https://code.google.com/p/chromium/issues/detail?id=147402
- https://code.google.com/p/chromium/issues/detail?id=143798
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78841
More from google
View All →CVE-2025-24959
Environment Variable Injection for dotenv API in zx
Low
1
CVE-2024-45601
Local file Inclusion via static file serving functionality in Mesop
High
7.5
CVE-2022-3708
Web Stories <= 1.24.0 - Server Side Request Forgery
Critical
9.6
CVE-2022-31055
Improper Access Control in kctf
High
7.5
CVE-2022-23569
`CHECK`-fails when building invalid tensor shapes in Tensorflow
Medium
6.5
Affected Vendor
Affected Software
chrome
Vulnerable Versions:
0, 22.0.1229.0, 22.0.1229.1, 22.0.1229.2, 22.0.1229.3, 22.0.1229.4, 22.0.1229.6, 22.0.1229.7, 22.0.1229.8, 22.0.1229.9, 22.0.1229.10, 22.0.1229.11, 22.0.1229.12, 22.0.1229.14, 22.0.1229.16, 22.0.1229.17, 22.0.1229.18, 22.0.1229.20, 22.0.1229.21, 22.0.1229.22, 22.0.1229.23, 22.0.1229.24, 22.0.1229.25, 22.0.1229.26, 22.0.1229.27, 22.0.1229.28, 22.0.1229.29, 22.0.1229.31, 22.0.1229.32, 22.0.1229.33, 22.0.1229.35, 22.0.1229.36, 22.0.1229.37, 22.0.1229.39, 22.0.1229.48, 22.0.1229.49, 22.0.1229.50, 22.0.1229.51, 22.0.1229.52, 22.0.1229.53, 22.0.1229.54, 22.0.1229.55, 22.0.1229.56, 22.0.1229.57, 22.0.1229.58, 22.0.1229.59, 22.0.1229.60, 22.0.1229.62, 22.0.1229.63, 22.0.1229.64, 22.0.1229.65, 22.0.1229.67, 22.0.1229.76
Timeline
Official Publish:
September 26th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.