FlawAtlas
Search the atlas
CVE-2023-5217 High

Confirmed as exploited

Electron affected by libvpx's heap buffer overflow in vp8 encoding

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit probability 49.0%
Published September 28, 2023
Required by October 23, 2023
Last source change July 1, 2026

01 / ACTION

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

11 explicit affected versions

npm electron

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2024:14572-1

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2023-5217

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

View original source
Open Source Vulnerabilities CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

View original source
Open Source Vulnerabilities GHSA-qqvq-6xgj-jw8g

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

View original source

05 / REFERENCES

Further evidence