7.5
CVSSv3

CVE-2010-4577

Published: 22/12/2010 Updated: 02/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome prior to 8.0.552.224, Chrome OS prior to 8.0.552.343, webkitgtk prior to 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote malicious users to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webkitgtk webkitgtk

google chrome os

google chrome

fedoraproject fedora 13

debian debian linux 7.0

debian debian linux 6.0

Vendor Advisories

Multiple security vulnerabilities were fixed in WebKit ...
Several vulnerabilities have been discovered in WebKit, a Web content engine library for GTK+ The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1783 WebKit does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of servic ...

Exploits

Konqueror version 473 suffers from a number of memory corruption vulnerabilities ...