CVE-2013-6649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
28/01/2014
Last modified:
11/04/2025

Description

Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 32.0.1700.101 (including)
cpe:2.3:a:google:chrome:32.0.1700.0:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.2:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.3:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.4:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.5:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.6:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.7:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.8:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.9:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.10:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.11:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.12:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.13:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:32.0.1700.14:*:*:*:*:*:*:*