HIGH 8.8 npm KEV

Electron affected by libvpx's heap buffer overflow in vp8 encoding

GHSA-qqvq-6xgj-jw8g · CVE-2023-5217

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes