CVE-2013-2903 - CVE House
Back to Database
Status published High CVE-2013-2903

Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink,...

Vulnerability Description

Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving moving a (1) AUDIO or (2) VIDEO element between documents.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2903

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

chrome, debian linux
Vulnerable Versions:
0, 29.0.1547.0, 29.0.1547.1, 29.0.1547.2, 29.0.1547.3, 29.0.1547.4, 29.0.1547.5, 29.0.1547.7, 29.0.1547.8, 29.0.1547.9, 29.0.1547.10, 29.0.1547.11, 29.0.1547.12, 29.0.1547.13, 29.0.1547.14, 29.0.1547.15, 29.0.1547.16, 29.0.1547.17, 29.0.1547.18, 29.0.1547.19, 29.0.1547.20, 29.0.1547.21, 29.0.1547.22, 29.0.1547.23, 29.0.1547.27, 29.0.1547.28, 29.0.1547.29, 29.0.1547.30, 29.0.1547.31, 29.0.1547.32, 29.0.1547.33, 29.0.1547.34, 29.0.1547.35, 29.0.1547.36, 29.0.1547.37, 29.0.1547.38, 29.0.1547.39, 29.0.1547.40, 29.0.1547.41, 29.0.1547.42, 29.0.1547.45, 29.0.1547.46, 29.0.1547.47, 29.0.1547.48, 29.0.1547.49, 29.0.1547.50, 29.0.1547.51, 29.0.1547.52, 29.0.1547.53, 29.0.1547.54, 29.0.1547.55, 7.0

Timeline

Official Publish: August 21st, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.