VulnerabilityModified
CVE-2013-2874
Google Chrome before 28.0.1500.71 on Windows, when an Nvidia GPU is used, allows remote attackers to bypass intended restrictions on access to screen data via vectors involving IPC transmission of GL textures.
MEDIUM 4.3EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 28.0.1500.71 on Windows, when an Nvidia GPU is used, allows remote attackers to bypass intended restrictions on access to screen data via vectors involving IPC transmission of GL textures.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html
- https://code.google.com/p/chromium/issues/detail?id=237611
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17142
- http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html
- https://code.google.com/p/chromium/issues/detail?id=237611
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17142
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.