NA
CVSSv3

CVE-2008-7061

CVSSv4: NA | CVSSv3: NA | CVSSv2: 4.3 | VMScore: 530 | EPSS: 0.09444 | KEV: Not Included
Published: 24/08/2009 Updated: 21/11/2024

Vulnerability Summary

The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions prior to 0.2.149.30 allows remote malicious users to cause a denial of service (CPU consumption or crash) via a tag with a long title attribute, which is not properly handled when displaying a tooltip, a different vulnerability than CVE-2008-6994. NOTE: there is inconsistent information about the environments under which this issue exists.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 0.2.149.29

Exploits

source: wwwsecurityfocuscom/bid/30975/info Google Chrome is prone to a remote denial-of-service vulnerability because it fails to handle user-supplied input Attackers can exploit this issue to make the application unresponsive, denying service to legitimate users Google Chrome 0214927 is vulnerable; other versions may also be affec ...

References

CWE-399https://nvd.nist.govhttps://www.exploit-db.com/exploits/32311/https://www.first.org/epsshttp://googlechromereleases.blogspot.com/2008/09/beta-release-0214930.htmlhttp://src.chromium.org/viewvc/chrome/trunk/src/chrome/browser/render_widget_host_hwnd.cc?r1=1287&r2=2042&pathrev=2042http://src.chromium.org/viewvc/chrome/trunk/src/chrome/views/tooltip_manager.cc?r1=1287&r2=2042&pathrev=2042http://src.chromium.org/viewvc/chrome?view=rev&revision=2042http://www.blackhat.org.il/exploits/chrome-freeze-exploit.htmlhttp://www.securityfocus.com/archive/1/496078/100/0/threadedhttp://www.securityfocus.com/archive/1/496094/100/0/threadedhttp://www.securityfocus.com/archive/1/496101/100/0/threadedhttp://www.securityfocus.com/archive/1/496126/100/0/threadedhttp://www.securityfocus.com/archive/1/496138/100/0/threadedhttp://www.securityfocus.com/archive/1/496145/100/0/threadedhttp://www.securityfocus.com/archive/1/496146/100/0/threadedhttp://www.securityfocus.com/archive/1/496151/100/0/threadedhttp://www.securityfocus.com/archive/1/496172/100/100/threadedhttp://www.securityfocus.com/bid/30975https://exchange.xforce.ibmcloud.com/vulnerabilities/45039http://googlechromereleases.blogspot.com/2008/09/beta-release-0214930.htmlhttp://src.chromium.org/viewvc/chrome/trunk/src/chrome/browser/render_widget_host_hwnd.cc?r1=1287&r2=2042&pathrev=2042http://src.chromium.org/viewvc/chrome/trunk/src/chrome/views/tooltip_manager.cc?r1=1287&r2=2042&pathrev=2042http://src.chromium.org/viewvc/chrome?view=rev&revision=2042http://www.blackhat.org.il/exploits/chrome-freeze-exploit.htmlhttp://www.securityfocus.com/archive/1/496078/100/0/threadedhttp://www.securityfocus.com/archive/1/496094/100/0/threadedhttp://www.securityfocus.com/archive/1/496101/100/0/threadedhttp://www.securityfocus.com/archive/1/496126/100/0/threadedhttp://www.securityfocus.com/archive/1/496138/100/0/threadedhttp://www.securityfocus.com/archive/1/496145/100/0/threadedhttp://www.securityfocus.com/archive/1/496146/100/0/threadedhttp://www.securityfocus.com/archive/1/496151/100/0/threadedhttp://www.securityfocus.com/archive/1/496172/100/100/threadedhttp://www.securityfocus.com/bid/30975https://exchange.xforce.ibmcloud.com/vulnerabilities/45039