6.8
CVSSv2

CVE-2013-2853

Published: 10/07/2013 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The HTTPS implementation in Google Chrome prior to 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle malicious users to have an unspecified impact via vectors that trigger header truncation.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 28.0.1500.68

google chrome 28.0.1500.26

google chrome 28.0.1500.31

google chrome 28.0.1500.0

google chrome 28.0.1500.33

google chrome 28.0.1500.29

google chrome 28.0.1500.25

google chrome 28.0.1500.66

google chrome 28.0.1500.41

google chrome 28.0.1500.12

google chrome 28.0.1500.13

google chrome 28.0.1500.62

google chrome 28.0.1500.20

google chrome 28.0.1500.39

google chrome 28.0.1500.60

google chrome 28.0.1500.15

google chrome 28.0.1500.59

google chrome 28.0.1500.23

google chrome 28.0.1500.45

google chrome 28.0.1500.43

google chrome 28.0.1500.40

google chrome 28.0.1500.3

google chrome 28.0.1500.52

google chrome 28.0.1500.34

google chrome 28.0.1500.46

google chrome 28.0.1500.8

google chrome 28.0.1500.63

google chrome 28.0.1500.53

google chrome 28.0.1500.4

google chrome 28.0.1500.36

google chrome 28.0.1500.44

google chrome 28.0.1500.51

google chrome 28.0.1500.19

google chrome 28.0.1500.2

google chrome 28.0.1500.50

google chrome 28.0.1500.56

google chrome 28.0.1500.54

google chrome 28.0.1500.18

google chrome 28.0.1500.27

google chrome 28.0.1500.21

google chrome 28.0.1500.14

google chrome 28.0.1500.9

google chrome 28.0.1500.16

google chrome 28.0.1500.37

google chrome 28.0.1500.6

google chrome 28.0.1500.47

google chrome 28.0.1500.42

google chrome 28.0.1500.11

google chrome 28.0.1500.17

google chrome 28.0.1500.28

google chrome 28.0.1500.49

google chrome 28.0.1500.35

google chrome 28.0.1500.61

google chrome 28.0.1500.48

google chrome 28.0.1500.22

google chrome 28.0.1500.64

google chrome 28.0.1500.24

google chrome 28.0.1500.58

google chrome 28.0.1500.10

google chrome 28.0.1500.32

google chrome

google chrome 28.0.1500.5

google chrome 28.0.1500.38

Vendor Advisories

Several vulnerabilities have been discovered in the Chromium web browser CVE-2013-2853 The HTTPS implementation does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline) CVE-2013-2867 Chrome does not properly prevent pop-under windows CVE-2013-2868 common/extensions/sync_helper ...