cpe:/a:google:chrome:0.2.149.27 CVE-2008-6995 2009-08-19T01:24:52.717-04:00 2017-09-28T21:33:28.200-04:00 4.3 NETWORK MEDIUM NONE NONE NONE PARTIAL http://nvd.nist.gov 2009-08-19T10:14:00.000-04:00 BUGTRAQ 20080902 Google Chrome Browser (ver.0.2.149.27) Vulnerability BID 30983 OSVDB 47908 EXPLOIT-DB 6353 XF google-chrome-handlers-dos(44899) CONFIRM http://code.google.com/p/chromium/issues/detail?id=122 MISC http://evilfingers.com/advisory/google_chrome_poc.php CONFIRM http://src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/net/base/escape.cc?r1=1757&r2=1760&pathrev=1760 MISC https://www.evilfingers.com/advisory/Google_Chrome_Browser_0.2.149.27_in_chrome_dll.php Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.