Уязвимость use-after-free в реализации каскадных таблиц стилей (CSS) в Google Chrome через run-in boxes
Описание
В браузере Google Chrome существует уязвимость use-after-free в реализации каскадных таблиц стилей (CSS), которая позволяет злоумышленникам вызвать DoS атаку или, возможно, оказывать иное неопределённое воздействие, используя определённые методы, связанные с run-in boxes.
Затронутые версии ПО
- Google Chrome < 18.0.1025.151
Тип уязвимости
- DoS атака
- Потенциальное иное воздействие
Ссылки
- Vendor Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- VDB Entry
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.
Use-after-free vulnerability in the Cascading Style Sheets (CSS) imple ...
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.
EPSS
6.8 Medium
CVSS2