9.3
CVSSv2

CVE-2012-1845

Published: 22/03/2012 Updated: 16/04/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in Google Chrome 17.0.963.66 and previous versions allows remote malicious users to bypass the DEP and ASLR protection mechanisms, and execute arbitrary code, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated "it really doesn't matter if it's third-party code."

Vulnerability Trend

Affected Products

Vendor Product Versions
GoogleChrome17.0.963.66