Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4863


Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)


Published

2023-09-12T15:15:24.327

Last Modified

2025-03-13T16:17:15.573

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google chrome < 116.0.5845.187 Yes
Operating System fedoraproject fedora 37 Yes
Operating System fedoraproject fedora 38 Yes
Operating System fedoraproject fedora 39 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes
Application mozilla firefox < 102.15.1 Yes
Application mozilla firefox < 117.0.1 Yes
Application mozilla firefox < 115.2.1 Yes
Application mozilla thunderbird < 102.15.1 Yes
Application mozilla thunderbird < 115.2.2 Yes
Application microsoft edge_chromium < 116.0.1938.81 Yes
Application microsoft teams < 1.6.00.26463 Yes
Application microsoft teams < 1.6.00.26474 Yes
Application microsoft webp_image_extension < 1.0.62681.0 Yes
Application webmproject libwebp < 1.3.2 Yes
Application netapp active_iq_unified_manager - Yes
Application bentley seequent_leapfrog < 2023.2 Yes
Application bandisoft honeyview < 5.51 Yes

References