CVE-2012-2864 describes an array overflow vulnerability in Mesa, specifically impacting Google Chrome on certain Acer and Samsung Chromebook and Chromebox models. This critical vulnerability (CVSS 10.0) allows remote attackers to execute arbitrary code with no authentication or user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.0.1180.0CPE matchmatch criteria | cpe:2.3:o:google:chrome_os:21.0.1180.0:*:*:*:*:*:*:* | ||
21.0.1180.1CPE matchmatch criteria | cpe:2.3:o:google:chrome_os:21.0.1180.1:*:*:*:*:*:*:* | ||
21.0.1180.2CPE matchmatch criteria | cpe:2.3:o:google:chrome_os:21.0.1180.2:*:*:*:*:*:*:* | ||
21.0.1180.3CPE matchmatch criteria | cpe:2.3:o:google:chrome_os:21.0.1180.3:*:*:*:*:*:*:* | ||
21.0.1180.4CPE matchmatch criteria | cpe:2.3:o:google:chrome_os:21.0.1180.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.