CVE-2013-2917 describes an out-of-bounds read vulnerability in the Web Audio implementation of Blink, specifically within the ReverbConvolverStage::ReverbConvolverStage function. This flaw affects Google Chrome versions prior to 30.0.1599.66. The vulnerability carries a CVSS score of 5.0, indicating a medium severity, and could lead to a denial of service (availability impact) without requiring authentication. There is no evidence of active exploitation, readily available exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 30.0.1599.65CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
30.0.1599.0CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.0:*:*:*:*:*:*:* | ||
30.0.1599.1CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.1:*:*:*:*:*:*:* | ||
30.0.1599.2CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.2:*:*:*:*:*:*:* | ||
30.0.1599.4CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.