We found results for “”
CVE-2023-4863
Good to know:
Date: September 12, 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Language: RUST
Severity Score
Related Resources (82)
Severity Score
Weakness Type (CWE)
Out-of-bounds Write
CWE-787Top Fix
Upgrade Version
Upgrade to version libwebp - 1.3.2;electron - 27.0.0-beta.2;electron - 22.3.24;electron - 24.8.3;electron - 25.8.1;electron - 26.2.1;github.com/chai2010/webp - v1.4.0;github.com/chai2010/webp - v0.0.0-20250406010349-76805d5a8860;github.com/chai2010/webp - v1.1.2-0.20250406010349-76805d5a8860;magick.net-q16-anycpu - 13.3.0;magick.net-q16-hdri-anycpu - 13.3.0;magick.net-q16-x64 - 13.3.0;magick.net-q8-anycpu - 13.3.0;magick.net-q8-openmp-x64 - 13.3.0;magick.net-q8-x64 - 13.3.0;skiasharp - 2.88.6;pillow - 10.0.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


