CVE-2012-2834 describes an integer overflow vulnerability in Google Chrome versions prior to 20.0.1132.43, specifically impacting the handling of crafted data within the Matroska container format. This flaw carries a critical CVSS score of 9.3, indicating that a remote attacker could exploit it with medium attack complexity to achieve a complete compromise of confidentiality, integrity, and availability, potentially leading to a denial of service or other unspecified impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, the vulnerability has received some community discussion and media coverage, suggesting it garnered attention at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.0.1132.42CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
20.0.1132.0CPE matchmatch criteria | cpe:2.3:a:google:chrome:20.0.1132.0:*:*:*:*:*:*:* | ||
20.0.1132.1CPE matchmatch criteria | cpe:2.3:a:google:chrome:20.0.1132.1:*:*:*:*:*:*:* | ||
20.0.1132.2CPE matchmatch criteria | cpe:2.3:a:google:chrome:20.0.1132.2:*:*:*:*:*:*:* | ||
20.0.1132.3CPE matchmatch criteria | cpe:2.3:a:google:chrome:20.0.1132.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.