CVE-2013-2924 is a use-after-free vulnerability in International Components for Unicode (ICU), affecting Google Chrome before version 30.0.1599.66 and other products. With a CVSS score of 7.5, it is a high-severity vulnerability that can be exploited remotely with low complexity, potentially leading to denial of service and possibly other unspecified impacts. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 30.0.1599.65CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
30.0.1599.0CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.0:*:*:*:*:*:*:* | ||
30.0.1599.1CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.1:*:*:*:*:*:*:* | ||
30.0.1599.2CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.2:*:*:*:*:*:*:* | ||
30.0.1599.4CPE matchmatch criteria | cpe:2.3:a:google:chrome:30.0.1599.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.