Sploitus

CVE-2013-6664

1 known exploit for CVE-2013-6664

Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving FORM elements, as demonstrated by use of the speech-recognition feature.

Affected products
Alt Linux, Google Chrome
Google Chrome
≤ 33.0.1750.144, 33.0.1750.0, 33.0.1750.1, 33.0.1750.2, 33.0.1750.3, 33.0.1750.4, 33.0.1750.5, 33.0.1750.6, 33.0.1750.7, 33.0.1750.8, 33.0.1750.9, 33.0.1750.10, 33.0.1750.11, 33.0.1750.12, 33.0.1750.13, 33.0.1750.14, 33.0.1750.15, 33.0.1750.16, 33.0.1750.18, 33.0.1750.19, 33.0.1750.20, 33.0.1750.21, 33.0.1750.22, 33.0.1750.23, 33.0.1750.24, 33.0.1750.25, 33.0.1750.26, 33.0.1750.27, 33.0.1750.28, 33.0.1750.29, 33.0.1750.30, 33.0.1750.31, 33.0.1750.34, 33.0.1750.35, 33.0.1750.36, 33.0.1750.37, 33.0.1750.38, 33.0.1750.39, 33.0.1750.40, 33.0.1750.41
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
1.3% (68th percentile)
Weakness
CWE-399
NVD status
Modified
Published
2014-03-05
CVE-2013-6664 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2013-6664

Proof-of-concept code and exploit modules indexed by Sploitus