CVE detail
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
21 source links · newest first
More than 60 of the Adobe, Google, Android, Microsoft, Mozilla and Apple zero-days that have come to light since 2016 attributed to spyware vendors.
newswww.securityweek.comFeb 6, 2024, 10:49 AMGoogle warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year.
newswww.securityweek.comDec 21, 2023, 9:50 AM- Google addressed a new actively exploited Chrome zero-daySecurity Affairs
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser. Google has released emergency updates to address a new zero-day vulnerability, tracked as CVE-2023-7024, in its web browser Chrome. The flaw has been addressed with the release of version 120.0.6099.129 for Mac,Linux and 120.0.6099.129/130 for Windows which will […]
newssecurityaffairs.comDec 20, 2023, 11:52 PM - CISA adds ownCloud and Google Chrome bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
US CISA added ownCloud and Google Chrome vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ownCloud and Google Chrome vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two issues are: CVE-2023-6345 – The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library that provides […]
newssecurityaffairs.comDec 1, 2023, 11:04 AM - Apple addressed 2 new iOS zero-day vulnerabilitiesSecurity Affairs
Apple released emergency security updates to fix two actively exploited zero-day flaws impacting iPhone, iPad, and Mac devices. Apple released emergency security updates to address two zero-day vulnerabilities impacting iPhone, iPad, and Mac devices. The flaws are actively exploited in attacks in the wild, both issues reside in the WebKit browser engine. The first vulnerability, […]
newssecurityaffairs.comNov 30, 2023, 10:33 PM - Google addressed the sixth Chrome Zero-Day vulnerability in 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-6345, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day, tracked as CVE-2023-6345, in the Chrome browser. The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library […]
newssecurityaffairs.comNov 29, 2023, 7:04 PM - Google Patches Seventh Chrome Zero-Day of 2023SecurityWeek
The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023.
newswww.securityweek.comNov 29, 2023, 12:18 PM - Google fixes Chrome zero day exploited in the wild (CVE-2023-6345)Help Net Security
Google has released an urgent security update to fix a number of vulnerabilities in Chrome browser, including a zero-day vulnerability (CVE-2023-6345) that is being actively exploited in the wild. About CVE-2023-6345 CVE-2023-6345, reported by Benoît Sevens and Clément Lecigne of Google’s Threat Analysis Group, is due to an integer overflow in Skia – an open source 2D graphics library commonly used as a graphics engine for Google Chrome, ChromeOS, Android, Flutter, and others. The company … More →
newswww.helpnetsecurity.comNov 29, 2023, 11:40 AM SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’.
newswww.securityweek.comOct 10, 2023, 1:58 PM- 9th October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 9th October, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES The American Rock County Public Health Department, which serves more than 160K people across Wisconsin area, has been a victim of a ransomware attack that forced officials to take some systems offline. Cuba […]
vendorresearch.checkpoint.comOct 9, 2023, 11:25 AM - October 2023 Patch Tuesday forecast: Operating system updates and zero-days aplentyHelp Net Security
UPDATE: October 10, 12:10 PM PT – October 2023 Patch Tuesday is now live: Microsoft fixes exploited WordPad, Skype for Business zero-days September has been a packed month of continuous updates. New operating systems were released from Apple and Microsoft, and several vulnerabilities exploited in web services resulted in a domino effect of zero-day releases for many vendors. If you haven’t rolled them out yet, they can be considered part of the forecast for next … More →
newswww.helpnetsecurity.comOct 6, 2023, 4:42 AM - Update now! Apple patches vulnerabilities on iPhone and iPadMalwarebytes Labs
Apple has released iOS 17.0.3, an emergency update fixing two vulnerabilities, one of which has already been exploited by cybercriminals. The update is…
newswww.malwarebytes.comOct 5, 2023, 2:23 PM - Apple patches another iOS zero-day under attack (CVE-2023-42824)Help Net Security
Apple has released a security update for iOS and iPadOS to fix another zero-day vulnerability (CVE-2023-42824) exploited in the wild. About CVE-2023-42824 CVE-2023-42824 is a kernel vulnerability that could allow a local threat actor to elevate its privileges on affected iPhones and iPads. “Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6,” the company stated. The vulnerability affects the following devices: iPhone XS … More →
newswww.helpnetsecurity.comOct 5, 2023, 10:46 AM - Apple fixed the 17th zero-day flaw exploited in attacksSecurity Affairs
Apple released emergency security updates to address a new actively exploited zero-day vulnerability impacting iPhone and iPad devices. Apple released emergency security updates to address a new zero-day vulnerability, tracked as CVE-2023-42824, that is exploited in attacks targeting iPhone and iPad devices. The vulnerability is a privilege escalation issue that resides in the Kernel, it was addressed […]
newssecurityaffairs.comOct 4, 2023, 8:40 PM Companies have addressed the impact of the exploited Libwebp vulnerability CVE-2023-4863 on their products.
newswww.securityweek.comOct 3, 2023, 9:00 AM- 2nd October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 2nd October, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES Check Point researchers have detected a phishing campaign exploiting popular file-sharing program Dropbox. The threat actors use legitimate Dropbox pages to send official email messages to the victims, which will then redirect the […]
vendorresearch.checkpoint.comOct 2, 2023, 1:20 PM Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: How global enterprises navigate the complex world of data privacy In this Help Net Security interview, Evelyn de Souza, Head of Privacy Compliance, Oracle SaaS Cloud, talks about the constant efforts required to keep up with privacy laws in each country, and ensuring compliance across the entire organization. MITRE ATT&CK project leader on why the framework remains vital for cybersecurity … More →
newswww.helpnetsecurity.comOct 1, 2023, 8:00 AMGoogle has updated the Stable Channel for Chrome to 117.0.5938.132 for Windows, Mac and Linux. This update includes ten security fixes. According to…
newswww.malwarebytes.comSep 29, 2023, 11:24 AM- Yet another Chrome zero-day exploited in the wild! (CVE-2023-5217)Help Net Security
Google has fixed another critical zero-day vulnerability (CVE-2023-5217) in Chrome that is being exploited in the wild. About CVE-2023-5217 The vulnerability is caused by a heap buffer overflow in vp8 encoding in libvpx – a video codec library from Google and the Alliance for Open Media (AOMedia). CVE-2023-5217 has been fixed in Google Chrome 117.0.5938.132 for Windows, Mac and Linux users. Google noted that the exploit for CVE-2023-5217 exists in the wild, so users are … More →
newswww.helpnetsecurity.comSep 28, 2023, 11:46 AM Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor.
newswww.securityweek.comSep 28, 2023, 9:48 AM- GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-5217, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day flaw in the Chrome browser which is tracked as CVE-2023-5217. The CVE-2023-5217 is a high-severity heap buffer overflow that affects vp8 encoding in […]
newssecurityaffairs.comSep 28, 2023, 9:08 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-4863CVSS 8.8 · High
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pa…
- CVE-2020-16009CVSS 8.8 · High
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-15969CVSS 8.8 · High
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-19906CVSS 7.5 · High
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ul…
- CVE-2010-1205CVSS 9.8 · Critical
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG…
- CVE-2025-14174CVSS 8.8 · High
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chr…