Vulnerability · NVD
CVE-2013-6629
CVE-2013-6629, rated high by the vendor: 4 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 4.7
- Exploitation
- 9.7 %
- Tracked apps
- 4
- Still exposed
- 0
Base CVSS ; severity is a vendor rating (different scale)
EPSS, predicted over 30 days
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
NVD references 11 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2016 (Server Core installation) Fixed in -
- Windows Server 2016 Fixed in -
- Windows 10 1703 · 2017-03 Fixed in -
- Windows 10 1607 · 2016-07 Fixed in -
- Windows 10 1511 · 2015-11 Fixed in -
Vulnerable CPE configurations (5)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <31.0.1650.48 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <31.0.1650.48 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
| mozilla |
firefox All platforms (wildcard)
|
All platforms (wildcard) | <24.2 | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
| mozilla |
firefox All platforms (wildcard)
|
All platforms (wildcard) | <26.0 | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | <24.2.0 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.