[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-0655Date: (C)2010-02-18   (M)2023-12-22


Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023506
http://code.google.com/p/chromium/issues/detail?id=12523
http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html
http://secunia.com/secunia_research/2009-65/
http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
oval:org.mitre.oval:def:14069

CPE    46
cpe:/a:google:chrome:2.0.169.0
cpe:/a:google:chrome:1.0.154.59
cpe:/a:google:chrome:0.3.154.0
cpe:/a:google:chrome:0.3.154.3
...
CWE    1
CWE-399
OVAL    3
oval:org.secpod.oval:def:752
oval:org.secpod.oval:def:754
oval:org.secpod.oval:def:753

© SecPod Technologies