Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Oct 19, 2012 | Mar 19, 2010 |
| Suse | — | Upgrade libwebkit-develUpgrade libwebkit-1_0-2Upgrade webkit-jscUpgrade libwebkit-1_0-2-32bitUpgrade libwebkit-lang | Feb 17, 2015 | Mar 19, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub