Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2012-1846

CVE-2012-1846, Severity pending severity (CVSS —): 2 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
-
Exploitation
4.2 %

EPSS, predicted over 30 days

Tracked apps
2
Still exposed
0

Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated "it really doesn't matter if it's third-party code."

EPSS 4.23% above median percentile 90.3%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Chrome macOS com.google.Chrome
    Affected ≤17.0.963.66 Fixed in > 17.0.963.66 Latest tracked - undetermined
  • Google Chrome Windows winget:Google.Chrome
    Affected ≤17.0.963.66 Fixed in > 17.0.963.66 Latest tracked 152.0.7977.65 patched
Vulnerable CPE configurations (2)
Vendor Product Versions
google chrome
All platforms (wildcard)
≤17.0.963.66
google chrome
All platforms (wildcard)
≤17.0.963.66
View on NVD ↗