8.8
CVE-2022-2294
- EPSS 2.19%
- Published 28.07.2022 02:15:07
- Last modified 03.04.2025 16:08:44
- Source chrome-cve-admin@google.com
- Teams watchlist Login
- Open Login
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Data is provided by the National Vulnerability Database (NVD)
Fedoraproject ≫ Extra Packages For Enterprise Linux Version8.0
Fedoraproject ≫ Fedora Version35
Fedoraproject ≫ Fedora Version36
Wpewebkit ≫ Wpe Webkit Version < 2.36.5
Webrtc Project ≫ Webrtc Version-
25.08.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
WebRTC Heap Buffer Overflow Vulnerability
VulnerabilityWebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.19% | 0.838 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.