Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade webkit-gtk2 | Dec 10, 2025 | Jul 18, 2010 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jun 11, 2012 | Sep 24, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 7, 2010 |
| Suse | — | Upgrade webkit-jscUpgrade libwebkit-1_0-2-32bitUpgrade libwebkit-1_0-2Upgrade libwebkit-develUpgrade libwebkit-lang | Feb 17, 2015 | Sep 24, 2010 |
| Ubuntu | — | Upgrade chromium-browserUpgrade webkit | Nov 19, 2024 | Sep 24, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub