Back to Database
Status published
Critical
CVE-2013-2870
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers...
Vulnerability Description
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2870
Credits & Attribution
No credits recorded in the NVD database.
References
- http://git.chromium.org/gitweb/?p=chromium/chromium.git%3Ba=commit%3Bh=2b0ff6d8a832f4fe5c187b17342b56675fbf7b96
- https://code.google.com/p/chromium/issues/detail?id=244746
- http://git.chromium.org/gitweb/?p=chromium/chromium.git%3Ba=commit%3Bh=5449227016f44d7c023b28a697ada40064c681a6
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16723
- http://www.debian.org/security/2013/dsa-2724
- https://code.google.com/p/chromium/issues/detail?id=242762
- http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html
More from google
View All →CVE-2025-24959
Environment Variable Injection for dotenv API in zx
Low
1
CVE-2024-45601
Local file Inclusion via static file serving functionality in Mesop
High
7.5
CVE-2022-3708
Web Stories <= 1.24.0 - Server Side Request Forgery
Critical
9.6
CVE-2022-31055
Improper Access Control in kctf
High
7.5
CVE-2022-23569
`CHECK`-fails when building invalid tensor shapes in Tensorflow
Medium
6.5
Affected Vendor
Affected Software
chrome, debian linux
Vulnerable Versions:
0, 28.0.1500.0, 28.0.1500.2, 28.0.1500.3, 28.0.1500.4, 28.0.1500.5, 28.0.1500.6, 28.0.1500.8, 28.0.1500.9, 28.0.1500.10, 28.0.1500.11, 28.0.1500.12, 28.0.1500.13, 28.0.1500.14, 28.0.1500.15, 28.0.1500.16, 28.0.1500.17, 28.0.1500.18, 28.0.1500.19, 28.0.1500.20, 28.0.1500.21, 28.0.1500.22, 28.0.1500.23, 28.0.1500.24, 28.0.1500.25, 28.0.1500.26, 28.0.1500.27, 28.0.1500.28, 28.0.1500.29, 28.0.1500.31, 28.0.1500.32, 28.0.1500.33, 28.0.1500.34, 28.0.1500.35, 28.0.1500.36, 28.0.1500.37, 28.0.1500.38, 28.0.1500.39, 28.0.1500.40, 28.0.1500.41, 28.0.1500.42, 28.0.1500.43, 28.0.1500.44, 28.0.1500.45, 28.0.1500.46, 28.0.1500.47, 28.0.1500.48, 28.0.1500.49, 28.0.1500.50, 28.0.1500.51, 28.0.1500.52, 28.0.1500.53, 28.0.1500.54, 28.0.1500.56, 28.0.1500.58, 28.0.1500.59, 28.0.1500.60, 28.0.1500.61, 28.0.1500.62, 28.0.1500.63, 28.0.1500.64, 28.0.1500.66, 28.0.1500.68, 7.0
Timeline
Official Publish:
July 10th, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.