8.8
CVSSv3

CVE-2022-4907

Published: 29/07/2023 Updated: 28/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Uninitialized Use in FFmpeg in Google Chrome before 108.0.5359.71 allowed a remote malicious user to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

fedoraproject fedora 37

fedoraproject fedora 38

debian debian linux 12.0

Vendor Advisories

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed For the stable distribution (bookworm), this problem has been fixed in version 7:514-0+deb12u1 We recommend that you upgrade your ffmpeg ...